{"id":"CVE-2026-98117","title":"In the Linux kernel, the following vulnerability has been resolved:\n\ncachefiles: Fix potential UAF/KASAN warning\n\nCurrently, trace_cachefiles_coherency() is being passed a pointer to a\n__be64 lain over the coherency data in struct cachef…","summary":"In the Linux kernel, the following vulnerability has been resolved:\n\ncachefiles: Fix potential UAF/KASAN warning\n\nCurrently, trace_cachefiles_coherency() is being passed a pointer to a\n__be64 lain over the coherency data in struct cachef…","severity":"none","vendor":"Linux","product":"Linux","affected":["Linux >= 229105e5cfd9832a9ef1368c96e0098ec3a5fbf0 < 68d459e6e609c31f96a203dd6eec60c634f155e1","Linux >= 229105e5cfd9832a9ef1368c96e0098ec3a5fbf0 < 93488ea378b4427598cace558236c110515d743b","Linux >= 229105e5cfd9832a9ef1368c96e0098ec3a5fbf0 < a67632c8c2688d6e0091529bcefe54bc5ee80e9b","Linux 6.14"],"published":"2026-09-25","updated":"2026-09-25","sourceUpdated":"2026-09-25T11:17:42.920","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-98117","references":[{"url":"https://git.kernel.org/stable/c/68d459e6e609c31f96a203dd6eec60c634f155e1","label":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/93488ea378b4427598cace558236c110515d743b","label":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/a67632c8c2688d6e0091529bcefe54bc5ee80e9b","label":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}],"tags":["nvd","cve.org"],"ingestedAt":"2026-09-25T11:06:38.821Z","slug":"CVE-2026-98117","body":"## Overview\n\nIn the Linux kernel, the following vulnerability has been resolved:\n\ncachefiles: Fix potential UAF/KASAN warning\n\nCurrently, trace_cachefiles_coherency() is being passed a pointer to a\n__be64 lain over the coherency data in struct cachefiles_xattr so that it\ncan display the first 8 bytes.  However, the data is of variable length and\ncould even be 0 bytes.  This could lead to a UAF or KASAN warning.\n\nFix this by making sure the buffer has room for at least 8 bytes and that\nthose 8 bytes are pre-cleared.\n\nFurther, those bytes are not 8-byte aligned, so fix the tracepoint to\nextract the data as four 2-byte words (they are 2-byte aligned) and\nreassemble the __be64.  The compiler will convert this into a single 8-byte\nload where the CPU supports it.\n\n## Remediation\n\nRefer to the linked advisories for vendor-supplied fixes and affected version ranges.","depth":"sunlit","depthScore":3,"depthScoreParts":{"impact":2.8,"likelihood":0,"exploitation":0,"ransomware":0},"changes":[]}