cifs: fix loff_t underflow in cifs_remap_file_range() when len == 0
Summary
| CVE | CVE-2026-89640 |
|---|---|
| State | PUBLISHED |
| Assigner | Linux |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2026-09-11 20:19:49 UTC |
| Updated | 2026-09-14 13:19:16 UTC |
| Description | In the Linux kernel, the following vulnerability has been resolved: cifs: fix loff_t underflow in cifs_remap_file_range() when len == 0 With len == 0 (clone to EOF), the effective length is computed as: len = src_inode->i_size - off; If off > i_size, this is a negative loff_t, corrupting the ByteCount in the FSCTL_DUPLICATE_EXTENTS_TO_FILE request and inverting the range in filemap_write_and_wait_range(). The existing off >= i_size check fires only after the ioctl has already been sent. Snapshot i_size_read() once for both the bounds check and the length calculation, eliminating the TOCTOU and 32-bit torn-read risk. Reject off > src_size with -EINVAL. Treat off == src_size as a no-op, consistent with __generic_remap_file_range_prep(). |
Risk And Classification
Primary CVSS: v3.1 7.1 HIGH from 416baaa9-dc9f-4396-8d5f-8c081fb06d67
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H
EPSS: 0.001250000 probability, percentile 0.025390000 (date 2026-09-14)
| Version | Source | Type | Score | Severity | Vector |
|---|---|---|---|---|---|
| 3.1 | 416baaa9-dc9f-4396-8d5f-8c081fb06d67 | Secondary | 7.1 | HIGH | CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H |
| 3.1 | CNA | DECLARED | 7.1 | HIGH | CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H |
CVSS v3.1 Breakdown
Attack Vector
LocalAttack Complexity
LowPrivileges Required
LowUser Interaction
NoneScope
UnchangedConfidentiality
NoneIntegrity
HighAvailability
HighCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H
Vendor Declared Affected Products
| Source | Vendor | Product | Version | Platforms |
|---|---|---|---|---|
| CNA | Linux | Linux | affected 04b38d601239b4d9be641b412cf4b7456a041c67 f3d1ae1e6bc4a9f559185b6e7bd2b6375ec2fdd4 git | Not specified |
| CNA | Linux | Linux | affected 04b38d601239b4d9be641b412cf4b7456a041c67 7f62817fe049b0f3652518c1ba72631ec1e0a322 git | Not specified |
| CNA | Linux | Linux | affected 04b38d601239b4d9be641b412cf4b7456a041c67 b098f5e5858797827666e6cd73033f52fc39b5f6 git | Not specified |
| CNA | Linux | Linux | affected 04b38d601239b4d9be641b412cf4b7456a041c67 c2a0dcb5a7a1516aa6eb6d5cedca6a8e76527028 git | Not specified |
| CNA | Linux | Linux | affected 04b38d601239b4d9be641b412cf4b7456a041c67 b057ca17b656345d04669cb87f2aff9b31d873db git | Not specified |
| CNA | Linux | Linux | affected 04b38d601239b4d9be641b412cf4b7456a041c67 6c322f5cf7476ded7a9a20f7be72462065a03c68 git | Not specified |
| CNA | Linux | Linux | affected 4.5 | Not specified |
| CNA | Linux | Linux | unaffected 4.5 semver | Not specified |
| CNA | Linux | Linux | unaffected 6.1.188 6.1.* semver | Not specified |
| CNA | Linux | Linux | unaffected 6.6.157 6.6.* semver | Not specified |
| CNA | Linux | Linux | unaffected 6.12.109 6.12.* semver | Not specified |
| CNA | Linux | Linux | unaffected 6.18.50 6.18.* semver | Not specified |
| CNA | Linux | Linux | unaffected 7.2.4 7.2.* semver | Not specified |
| CNA | Linux | Linux | unaffected 7.3-rc1 * original_commit_for_fix | Not specified |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| git.kernel.org/stable/c/7f62817fe049b0f3652518c1ba72631ec1e0a322 | 416baaa9-dc9f-4396-8d5f-8c081fb06d67 | git.kernel.org | |
| git.kernel.org/stable/c/6c322f5cf7476ded7a9a20f7be72462065a03c68 | 416baaa9-dc9f-4396-8d5f-8c081fb06d67 | git.kernel.org | |
| git.kernel.org/stable/c/b098f5e5858797827666e6cd73033f52fc39b5f6 | 416baaa9-dc9f-4396-8d5f-8c081fb06d67 | git.kernel.org | |
| git.kernel.org/stable/c/c2a0dcb5a7a1516aa6eb6d5cedca6a8e76527028 | 416baaa9-dc9f-4396-8d5f-8c081fb06d67 | git.kernel.org | |
| git.kernel.org/stable/c/b057ca17b656345d04669cb87f2aff9b31d873db | 416baaa9-dc9f-4396-8d5f-8c081fb06d67 | git.kernel.org | |
| git.kernel.org/stable/c/f3d1ae1e6bc4a9f559185b6e7bd2b6375ec2fdd4 | 416baaa9-dc9f-4396-8d5f-8c081fb06d67 | git.kernel.org | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.