Description
In the Linux kernel, the following vulnerability has been resolved:

fuse: invalidate the correct range after O_APPEND direct write

fuse_direct_write_iter() captures pos before generic_write_checks(),
which moves ki_pos to EOF for O_APPEND writes:

fuse_direct_write_iter()
{
pos = iocb->ki_pos; /* 0 (user-supplied) */
generic_write_checks(); /* ki_pos -> EOF */
fuse_direct_io(); /* writes at EOF, correct */
invalidate(pos, pos + res); /* [0, res) -- wrong */
}

The post-write invalidation targets a stale range instead of the
actual written range at EOF.

This can cause data inconsistency when the file size is not
page-aligned. The tail page straddling EOF has a valid portion
before EOF that concurrent readers can fault back in during the
DIO write window:

Tail page (file size X not page-aligned):

page_start X (EOF) page_end
|--- valid data ----|-- stale --|

CPU0 (O_APPEND DIO writer) CPU1 (buffered reader)
-------------------------- ----------------------
invalidate [X, X+len)
tail page evicted
FUSE_WRITE in flight ...
read [page_start, X)
tail page re-faulted
[X, page_end) = stale
FUSE_WRITE completes
i_size = X + len
invalidate [0, len) <- WRONG
tail page still cached
read [X, X+len)
hits stale tail page
returns old data

Fix by reading pos back from iocb->ki_pos after generic_write_checks(),
as generic_file_direct_write() does.

Also fix a typo in the comment ("may have" -> "may have competed").
Published: 2026-09-17
Score: n/a
EPSS: < 1% Very Low
KEV: No
Impact: Data inconsistency leading to file corruption
Action: Immediate Update
AI Analysis

Impact

The Linux kernel issue arises when a FUSE filesystem receives an O_APPEND direct‑write operation. The implementation captures the original offset before the generic write checks, but the generic logic moves the file pointer to the end of file for O_APPEND writes. After the write completes, the kernel invalidates a stale range based on the original offset, leaving the tail page that crosses the old EOF still cached. Consequently, concurrent readers can fault back stale data from that cached page and receive incorrect file contents, resulting in visible data inconsistency or corruption.

Affected Systems

Any system running a Linux kernel that supports FUSE, before the patch that remediates the write‑position handling. Specific versions are not listed in the advisory; therefore all kernel releases lacking the fix are potentially affected.

Risk and Exploitability

Exploit likelihood is low (EPSS < 1%) and the vulnerability is not listed in the CISA KEV catalog. Based on the description, the likely attack vector is local; it requires an attacker who can open a file for O_APPEND direct write on a mounted FUSE filesystem. While no remote code execution is enabled, an attacker can corrupt file contents, potentially affecting downstream applications that rely on the affected data. The absence of a CVSS score limits precise severity assessment, but the combination of low exploitation probability and data‑corruption impact suggests a moderate risk that should be mitigated promptly.

Generated by OpenCVE AI on September 19, 2026 at 00:18 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Apply the Linux kernel update that includes the FUSE offset‑validation fix and reboot the system to load the corrected kernel
  • Remount affected FUSE filesystems (or restart dependent services) to clear stale cached pages
  • Consider disabling O_APPEND or using buffered writes on critical FUSE mounts until a kernel update is available

Generated by OpenCVE AI on September 19, 2026 at 00:18 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sat, 19 Sep 2026 00:45:00 +0000

Type Values Removed Values Added
Weaknesses CWE-665

Thu, 17 Sep 2026 16:30:00 +0000

Type Values Removed Values Added
Description In the Linux kernel, the following vulnerability has been resolved: fuse: invalidate the correct range after O_APPEND direct write fuse_direct_write_iter() captures pos before generic_write_checks(), which moves ki_pos to EOF for O_APPEND writes: fuse_direct_write_iter() { pos = iocb->ki_pos; /* 0 (user-supplied) */ generic_write_checks(); /* ki_pos -> EOF */ fuse_direct_io(); /* writes at EOF, correct */ invalidate(pos, pos + res); /* [0, res) -- wrong */ } The post-write invalidation targets a stale range instead of the actual written range at EOF. This can cause data inconsistency when the file size is not page-aligned. The tail page straddling EOF has a valid portion before EOF that concurrent readers can fault back in during the DIO write window: Tail page (file size X not page-aligned): page_start X (EOF) page_end |--- valid data ----|-- stale --| CPU0 (O_APPEND DIO writer) CPU1 (buffered reader) -------------------------- ---------------------- invalidate [X, X+len) tail page evicted FUSE_WRITE in flight ... read [page_start, X) tail page re-faulted [X, page_end) = stale FUSE_WRITE completes i_size = X + len invalidate [0, len) <- WRONG tail page still cached read [X, X+len) hits stale tail page returns old data Fix by reading pos back from iocb->ki_pos after generic_write_checks(), as generic_file_direct_write() does. Also fix a typo in the comment ("may have" -> "may have competed").
Title fuse: invalidate the correct range after O_APPEND direct write
First Time appeared Linux
Linux linux Kernel
CPEs cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
Vendors & Products Linux
Linux linux Kernel
References

Subscriptions

Linux Linux Kernel
cve-icon MITRE

Status: PUBLISHED

Assigner: Linux

Published:

Updated: 2026-09-17T16:06:08.870Z

Reserved: 2026-09-11T19:38:34.786Z

Link: CVE-2026-90096

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-09-17T17:17:01.233

Modified: 2026-09-17T17:17:01.233

Link: CVE-2026-90096

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-19T00:30:16Z

Weaknesses