CVE-2026-89640Medium· 5.5▾ SunlitA flaw was found in the Linux kernel's Common Internet File System (CIFS) implementation. When performing a file range remapping operation with a zero length, an integer underflow can occur if the offset exceeds the file size. This can lea…
▾ Sunlit zone — Low / medium · no exploitation signal
impact 30.3 · likelihood 0 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Exploit-prediction probability, daily snapshots since Sep 12.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via CSAF
0.2%
— → 6.3
none → medium
— → 6.3
none → medium
— → 7.1
none → high
7.1 → 6.3
high → medium
6.3 → 7.1
medium → high
Last analysed / modified upstream
7.1 → 5.5
high → medium
A flaw was found in the Linux kernel's Common Internet File System (CIFS) implementation. When performing a file range remapping operation with a zero length, an integer underflow can occur if the offset exceeds the file size. This can lead to corruption of the byte count in file system control requests, potentially causing unexpected behavior or data integrity issues. The vulnerability is resolved by correctly validating the offset against the file size before calculating the length, preventing the underflow.
kernel: cifs: fix loff_t underflow in cifs_remap_file_range() when len == 0 — rated Low by Red Hat. Released 2026-09-11, updated 2026-09-15.
Affected:
No fix planned:
Not affected:
Fix deferred
Field changes observed since this record was first indexed.
Connected by shared product, vendor, weakness, or advisory.
CVE-2026-80986High· 7.0kernel: net/smc: bound the peer rkey counts in SMC-Rv2 LLC messages (CVE-2026-80986)
CVE-2026-80944High· 7.0kernel: wifi: mwifiex: Detach sync cmd buffer on interrupted wait (CVE-2026-80944)
CVE-2026-80951High· 7.0kernel: i3c: master: svc: bound IBI payload to the requested max_payload_len (CVE-2026-80951)
CVE-2026-81002High· 7.0kernel: xdp: fix zero-copy frame layout (CVE-2026-81002)
CVE-2026-89438Medium· 5.5kernel: platform/x86: ISST: Validate logical CPU id and clos id (CVE-2026-89438)
CVE-2026-89482High· 7.0kernel: nvme-tcp: do not accept C2HData based on blk_rq_payload_bytes() alone (CVE-2026-89482)