Description
In the Linux kernel, the following vulnerability has been resolved:

ksmbd: Do not skip lock checks for single-byte ranges

check_lock_range() uses inclusive ranges. Its callers pass the end
offset as start + length - 1, so start == end represents a valid
single-byte range rather than an empty range.

The start == end shortcut therefore skips mandatory byte-range lock
checks for one-byte reads, writes, copychunk operations and one-byte
truncate ranges. A conflicting lock covering that byte is not checked
and the operation is allowed to proceed.

Remove the shortcut. The truncate size == inode->i_size case is already
handled by only calling check_lock_range() when the new size differs
from the current file size.
Published: 2026-09-17
Score: 8.1 High
EPSS: < 1% Very Low
KEV: No
Impact: Data Integrity Compromise
Action: Apply Patch
AI Analysis

Impact

A flaw in the Linux kernel’s ksmbd component prevents mandatory byte‑range lock checks when the range is a single byte. The check uses inclusive bounds but callers compute the end offset as start plus length minus one, so a one‑byte range is interpreted as empty and the lock check is skipped. This allows concurrent operations to bypass locking controls for reads, writes, copychunk and truncate operations that affect that byte, leading to potential data corruption or loss. The weakness is a race condition (CWE‑362 and CWE‑367).

Affected Systems

Affected systems are all Linux kernel installations that enable the ksmbd SMB server. No specific kernel version numbers are listed in the CVE data; the issue applies broadly to any kernel build that has not yet incorporated the commit that removes the shortcut.

Risk and Exploitability

The CVSS score of 8.1 indicates a high severity rating for this race condition flaw. The EPSS score of less than 1% suggests that, as of this assessment, the likelihood of exploitation is low, and the vulnerability is not currently listed in the CISA KEV catalog. Nonetheless, the flaw can be exploited for data integrity attacks, especially in environments where SMB shares are exposed to untrusted clients. The attack vector is inferred to be local or network‑based SMB access to a Linux host running ksmbd, as the omission occurs during byte‑range handling in file operations over SMB.

Generated by OpenCVE AI on September 28, 2026 at 13:39 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade the Linux kernel to a version that includes the commit removing the accept‑shortcut in check_lock_range()
  • Reboot the affected host to load the updated kernel
  • If an update cannot be applied immediately, disable the ksmbd service or block SMB traffic to the host until a patched kernel is available

Generated by OpenCVE AI on September 28, 2026 at 13:39 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Debian DLA Debian DLA DLA-4817-1 linux-6.12 security update
Debian DSA Debian DSA DSA-6528-1 linux security update
History

Mon, 28 Sep 2026 12:15:00 +0000


Sun, 20 Sep 2026 04:45:00 +0000

Type Values Removed Values Added
Weaknesses CWE-362

Sun, 20 Sep 2026 02:45:00 +0000

Type Values Removed Values Added
Weaknesses CWE-362

Sat, 19 Sep 2026 03:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-362

Fri, 18 Sep 2026 21:30:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 8.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N'}


Thu, 17 Sep 2026 16:30:00 +0000

Type Values Removed Values Added
Description In the Linux kernel, the following vulnerability has been resolved: ksmbd: Do not skip lock checks for single-byte ranges check_lock_range() uses inclusive ranges. Its callers pass the end offset as start + length - 1, so start == end represents a valid single-byte range rather than an empty range. The start == end shortcut therefore skips mandatory byte-range lock checks for one-byte reads, writes, copychunk operations and one-byte truncate ranges. A conflicting lock covering that byte is not checked and the operation is allowed to proceed. Remove the shortcut. The truncate size == inode->i_size case is already handled by only calling check_lock_range() when the new size differs from the current file size.
Title ksmbd: Do not skip lock checks for single-byte ranges
First Time appeared Linux
Linux linux Kernel
CPEs cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
Vendors & Products Linux
Linux linux Kernel
References

Subscriptions

Linux Linux Kernel
cve-icon MITRE

Status: PUBLISHED

Assigner: Linux

Published:

Updated: 2026-09-18T17:53:36.125Z

Reserved: 2026-09-11T19:38:34.791Z

Link: CVE-2026-90176

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-09-17T17:17:11.387

Modified: 2026-09-18T18:17:45.533

Link: CVE-2026-90176

cve-icon Redhat

Severity : Moderate

Publid Date: 2026-09-17T00:00:00Z

Links: CVE-2026-90176 - Bugzilla

cve-icon OpenCVE Enrichment

Updated: 2026-09-28T13:45:18Z

Weaknesses
  • CWE-362

    Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition')

  • CWE-367

    Time-of-check Time-of-use (TOCTOU) Race Condition