---
id: CVE-2026-98124
title: |-
  In the Linux kernel, the following vulnerability has been resolved:

  smb/client: invalidate fscache for fallocate range operations

  smb3_zero_range(), smb3_punch_hole(), smb3_insert_range(), and
  smb3_collapse_range() modify file contents…
summary: |-
  In the Linux kernel, the following vulnerability has been resolved:

  smb/client: invalidate fscache for fallocate range operations

  smb3_zero_range(), smb3_punch_hole(), smb3_insert_range(), and
  smb3_collapse_range() modify file contents…
severity: none
vendor: Linux
product: Linux
affected:
  - >-
    Linux >= 31742c5a331766bc7df6b0d525df00c6cd20d5a6 <
    93c6e5a8d7c5071d586c1411596d5db5faad22b2
  - >-
    Linux >= 31742c5a331766bc7df6b0d525df00c6cd20d5a6 <
    448ba0ae65ca61064183564d2983c9aa59bd6ba7
  - Linux 3.17
published: '2026-09-25'
updated: '2026-09-25'
sourceUpdated: '2026-09-25T11:17:43.720'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-98124'
references:
  - url: 'https://git.kernel.org/stable/c/448ba0ae65ca61064183564d2983c9aa59bd6ba7'
    label: 416baaa9-dc9f-4396-8d5f-8c081fb06d67
  - url: 'https://git.kernel.org/stable/c/93c6e5a8d7c5071d586c1411596d5db5faad22b2'
    label: 416baaa9-dc9f-4396-8d5f-8c081fb06d67
tags:
  - nvd
  - cve.org
ingestedAt: '2026-09-25T11:06:38.819Z'
---

## Overview

In the Linux kernel, the following vulnerability has been resolved:

smb/client: invalidate fscache for fallocate range operations

smb3_zero_range(), smb3_punch_hole(), smb3_insert_range(), and
smb3_collapse_range() modify file contents through server-side range
operations. These operations discard the affected page cache, but leave
the FS-Cache cookie valid, so a later read may return data cached before
the range operation.

Fix this by invalidating FS-Cache after outstanding I/O has completed
and before modifying the file on the server.

Run the following as root on a CIFS mount with fsc enabled and an active
CacheFiles backend:

        bash -c '
                MNT=/mnt/cifs
                FILE="$MNT/repro"

                # Generate four 1 MiB random blocks: [A][B][C][D].
                dd if=/dev/urandom of=/tmp/src bs=1M count=4 status=none

                # Expected contents after zeroing B: [A][zero][C][D].
                cp /tmp/src /tmp/expected
                dd if=/dev/zero of=/tmp/expected bs=1M seek=1 count=1 \
                        conv=notrunc status=none
                cp /tmp/src "$FILE"

                # Populate FS-Cache, then discard the page cache.
                sync
                echo 1 > /proc/sys/vm/drop_caches
                cat "$FILE" > /dev/null
                sync
                echo 1 > /proc/sys/vm/drop_caches

                fallocate --zero-range -o 1M -l 1M "$FILE"

                if cmp -s /tmp/expected "$FILE"; then
                        echo "readback: OK"
                else
                        echo "readback: STALE DATA"
                fi
        '

Before this change, the readback differs from /tmp/expected:

        readback: STALE DATA

After this change, it matches:

        readback: OK

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
