{"id":"CVE-2026-89642","title":"kernel: cifs: call pagecache_isize_extended() in cifs_setsize() when extending (CVE-2026-89642)","summary":"A flaw was found in the Linux kernel's Common Internet File System (CIFS) implementation. When a client extends a file, the `cifs_setsize()` function fails to properly zero out the newly extended portion of the page cache. This oversight c…","severity":"high","cvss":7,"cvssVector":"CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H","cvssSource":"vendor","cwe":"CWE-201","vendor":"Red Hat","product":"Red Hat Enterprise Linux 9","affected":["enterprise_linux 10","enterprise_linux 8","enterprise_linux 9","openshift_container_platform 4"],"published":"2026-09-11","updated":"2026-09-18","sourceUpdated":"2026-09-18T22:00:10+00:00","source":"CSAF","sourceUrl":"https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-89642.json","references":[{"url":"https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-89642.json"},{"url":"https://access.redhat.com/security/cve/CVE-2026-89642"},{"url":"https://bugzilla.redhat.com/show_bug.cgi?id=2532207"},{"url":"https://www.cve.org/CVERecord?id=CVE-2026-89642"},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2026-89642"},{"url":"https://git.kernel.org/pub/scm/linux/security/vulns.git/plain/cve/published/2026/CVE-2026-89642.mbox"},{"url":"https://git.kernel.org/stable/c/12bafe32f09c0d24f5096154b59c347b9c6606e0"},{"url":"https://git.kernel.org/stable/c/c510edb9734af1c274d18f4f31a471a166bbc7e8"}],"tags":["csaf","vex","red-hat","cve.org"],"epss":0.00155,"epssPercentile":0.05072,"ingestedAt":"2026-09-14T15:23:07.476Z","slug":"CVE-2026-89642","body":"## Overview\n\nA flaw was found in the Linux kernel's Common Internet File System (CIFS) implementation. When a client extends a file, the `cifs_setsize()` function fails to properly zero out the newly extended portion of the page cache. This oversight can lead to stale data from the client's memory being written back to the server, potentially exposing sensitive information to the server.\n\n## Vendor advisories\n\n- **Red Hat VEX** · Moderate · affected: Red Hat Enterprise Linux 10, Red Hat Enterprise Linux 8, Red Hat Enterprise Linux 9, Red Hat OpenShift Container Platform 4 · no fix planned: Red Hat Enterprise Linux 10, Red Hat Enterprise Linux 8, Red Hat Enterprise Linux 9, Red Hat OpenShift Container Platform 4 · updated 2026-09-18 · [vex](https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-89642.json)\n\n**kernel: cifs: call pagecache_isize_extended() in cifs_setsize() when extending** — rated Moderate by Red Hat. Released 2026-09-11, updated 2026-09-18.\n\nAffected:\n\n- Red Hat Enterprise Linux 10\n- Red Hat Enterprise Linux 8\n- Red Hat Enterprise Linux 9\n- Red Hat OpenShift Container Platform 4\n\nNo fix planned:\n\n- Red Hat Enterprise Linux 10\n- Red Hat Enterprise Linux 8\n- Red Hat Enterprise Linux 9\n- Red Hat OpenShift Container Platform 4\n\nNot affected:\n\n- Red Hat Enterprise Linux 6\n- Red Hat Enterprise Linux 7\n\n## Remediation\n\nAffected","depth":"twilight","depthScore":39,"depthScoreParts":{"impact":38.5,"likelihood":0,"exploitation":0,"ransomware":0},"changes":[{"seq":206925,"id":"CVE-2026-89642","ts":1789749703062,"field":"cvss","old":"6.5","new":"7"},{"seq":206924,"id":"CVE-2026-89642","ts":1789749703062,"field":"severity","old":"medium","new":"high"},{"seq":204057,"id":"CVE-2026-89642","ts":1789490231229,"field":"cvss","old":null,"new":"6.5"},{"seq":204056,"id":"CVE-2026-89642","ts":1789490231229,"field":"severity","old":"none","new":"medium"},{"seq":147550,"id":"CVE-2026-89642","ts":1789270211347,"field":"cvss","old":null,"new":"6.5"},{"seq":147549,"id":"CVE-2026-89642","ts":1789270211347,"field":"severity","old":"none","new":"medium"},{"seq":109302,"id":"CVE-2026-89642","ts":1789183731345,"field":"cvss","old":null,"new":"6.5"},{"seq":109301,"id":"CVE-2026-89642","ts":1789183731345,"field":"severity","old":"none","new":"medium"}]}