---
id: CVE-2026-90096
title: |-
  In the Linux kernel, the following vulnerability has been resolved:

  fuse: invalidate the correct range after O_APPEND direct write

  fuse_direct_write_iter() captures pos before generic_write_checks(),
  which moves ki_pos to EOF for O_APP…
summary: |-
  In the Linux kernel, the following vulnerability has been resolved:

  fuse: invalidate the correct range after O_APPEND direct write

  fuse_direct_write_iter() captures pos before generic_write_checks(),
  which moves ki_pos to EOF for O_APP…
severity: none
vendor: Linux
product: Linux
affected:
  - >-
    Linux >= 2b0408d0284f4ff376cf5610fa8c9905e93c2541 <
    833963069adf86dcbdffd4e7d7b3171f95070b77
  - >-
    Linux >= 2b0408d0284f4ff376cf5610fa8c9905e93c2541 <
    26d7e1f5c407b5859122b5cd47d7ebbf4b4c1cd2
  - Linux 7.2
published: '2026-09-17'
updated: '2026-09-17'
sourceUpdated: '2026-09-17T17:17:01.233'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-90096'
references:
  - url: 'https://git.kernel.org/stable/c/26d7e1f5c407b5859122b5cd47d7ebbf4b4c1cd2'
    label: 416baaa9-dc9f-4396-8d5f-8c081fb06d67
  - url: 'https://git.kernel.org/stable/c/833963069adf86dcbdffd4e7d7b3171f95070b77'
    label: 416baaa9-dc9f-4396-8d5f-8c081fb06d67
tags:
  - nvd
  - cve.org
ingestedAt: '2026-09-17T16:21:47.891Z'
epss: 0.00198
epssPercentile: 0.08557
---

## Overview

In the Linux kernel, the following vulnerability has been resolved:

fuse: invalidate the correct range after O_APPEND direct write

fuse_direct_write_iter() captures pos before generic_write_checks(),
which moves ki_pos to EOF for O_APPEND writes:

  fuse_direct_write_iter()
  {
      pos = iocb->ki_pos;           /* 0 (user-supplied)       */
      generic_write_checks();       /* ki_pos -> EOF           */
      fuse_direct_io();             /* writes at EOF, correct  */
      invalidate(pos, pos + res);   /* [0, res) -- wrong       */
  }

The post-write invalidation targets a stale range instead of the
actual written range at EOF.

This can cause data inconsistency when the file size is not
page-aligned.  The tail page straddling EOF has a valid portion
before EOF that concurrent readers can fault back in during the
DIO write window:

  Tail page (file size X not page-aligned):

    page_start         X (EOF)   page_end
    |--- valid data ----|-- stale --|

  CPU0 (O_APPEND DIO writer)    CPU1 (buffered reader)
  --------------------------    ----------------------
  invalidate [X, X+len)
    tail page evicted
  FUSE_WRITE in flight ...
                                read [page_start, X)
                                  tail page re-faulted
                                  [X, page_end) = stale
  FUSE_WRITE completes
  i_size = X + len
  invalidate [0, len)  <- WRONG
    tail page still cached
                                read [X, X+len)
                                  hits stale tail page
                                  returns old data

Fix by reading pos back from iocb->ki_pos after generic_write_checks(),
as generic_file_direct_write() does.

Also fix a typo in the comment ("may have" -> "may have competed").

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
