Answer in brief
CVE-2026-98126 records a Unknown severity vulnerability in smb/client: validate new EOF for zero range. The current sources do not mark it as known exploited. The current feed maps Linux/Linux (generic), Linux/Linux (generic). Check affected ranges and fixed versions before updating.
Analysis pending evidence review
HOL Guard separates source facts from reviewed analysis. See the methodology.
A CVSS score is not reported in the current record. The current sources do not mark it as known exploited. Treat this as a source-backed prioritization signal, not a statement about your environment.
Analysis status
Analysis pending evidence review
Factual feed record only; HOL analysis is not approved for indexing. Read the methodology.
The current feed maps Linux/Linux (generic), Linux/Linux (generic). Check affected ranges and fixed versions before updating.
| Package | Affected range | Fixed version |
|---|---|---|
| Linux/Linuxgeneric | >=72c419d9b073628d3b5b0b2fc787b724f1a8c726 <3673f057b64abfa957e8ae84448db69369a5091a || >=72c419d9b073628d3b5b0b2fc787b724f1a8c726 <06a4f9049cb6dc319bceec2dc813ba89add8b828 || >=72c419d9b073628d3b5b0b2fc787b724f1a8c726 <f320ca20c273a26cd779bdb2b2e4b076a95c76f6 || >=72c419d9b073628d3b5b0b2fc787b724f1a8c726 <88972e35750792e717af287dc71f42a03b5cbce4 | 3673f057b64abfa957e8ae84448db69369a5091a, 06a4f9049cb6dc319bceec2dc813ba89add8b828, f320ca20c273a26cd779bdb2b2e4b076a95c76f6, 88972e35750792e717af287dc71f42a03b5cbce4 |
| Linux/Linuxgeneric | 5.1 | Not reported |
Published upstream
Sep 25, 2026
Evidence: source:cvelist:source_dates:source-dates:recordSource modified
Sep 25, 2026
Evidence: source:cvelist:source_dates:source-dates:recordFirst seen by HOL
Sep 25, 2026
In the Linux kernel, the following vulnerability has been resolved: smb/client: validate new EOF for zero range When FALLOC_FL_ZERO_RANGE is used without FALLOC_FL_KEEP_SIZE, smb3_zero_range() may extend EOF without checking RLIMIT_FSIZE, allowing the file to grow beyond the caller's file-size limit. Fix this by calling inode_newsize_ok() before sending the zero-range request when the operation would extend EOF. Reproducer, using a file on a CIFS mount: bash -c ' FILE=/mnt/cifs/repro trap "" SIGXFSZ ulimit -f 3072 truncate -s 2M "$FILE" fallocate --zero-range -o 0 -l 4M "$FILE" echo "fallocate rc=$?" stat -c "file size=%s" "$FILE" ' Before this change, the operation succeeds despite the 3 MiB limit: fallocate rc=0 file size=4194304 After this change, fallocate fails and leaves the file at 2 MiB.
Quoted source text, attributed separately from HOL analysis.