CVE-2026-89639Medium· 5.5▾ SunlitA flaw was found in the Linux kernel's Common Internet File System (CIFS) implementation. When a file is truncated, the `cifs_do_truncate()` function does not properly invalidate the file system cache (fscache). This oversight can lead to …
▾ Sunlit zone — Low / medium · no exploitation signal
impact 30.3 · likelihood 0 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Exploit-prediction probability, daily snapshots since Sep 12.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via CSAF
0.2%
— → 3.3
none → low
— → 7.1
none → high
7.1 → 3.3
high → low
3.3 → 7.1
low → high
7.1 → 3.3
high → low
Last analysed / modified upstream
3.3 → 5.5
low → medium
A flaw was found in the Linux kernel's Common Internet File System (CIFS) implementation. When a file is truncated, the cifs_do_truncate() function does not properly invalidate the file system cache (fscache). This oversight can lead to stale cached data being served to users, potentially resulting in information disclosure or data inconsistency.
kernel: cifs: use cifs_invalidate_cache() in cifs_do_truncate() for O_TRUNC — rated Moderate by Red Hat. Released 2026-09-11, updated 2026-09-16.
Affected:
No fix planned:
Not affected:
Fix deferred
Field changes observed since this record was first indexed.
Connected by shared product, vendor, weakness, or advisory.
CVE-2026-80997Medium· 5.5kernel: net: ipa: fix stalled modem TX queue after runtime resume (CVE-2026-80997)
CVE-2026-89500High· 7.0kernel: ring-buffer: Make cpu_buffer::free_page a buffer_data_read_page (CVE-2026-89500)
CVE-2026-89503Medium· 5.5kernel: ring-buffer: Fix subbuf resize race with ring_buffer_alloc_read_page() (CVE-2026-89503)
CVE-2026-89570High· 7.0kernel: cxl/mce: Make the MCE notifier per-region (CVE-2026-89570)
CVE-2026-89584High· 7.0kernel: block: validate user space vectors during extraction (CVE-2026-89584)
CVE-2026-89681High· 7.0kernel: nfsd: fix layout fence worker double-reference race (CVE-2026-89681)