---
id: CVE-2026-98267
title: |-
  In the Linux kernel, the following vulnerability has been resolved:

  9p: Fix v9fs_issue_write() to update i_size and remote_i_size

  Fix v9fs_issue_write() to update i_size and remote_i_size to the new size
  of the server file if we made i…
summary: |-
  In the Linux kernel, the following vulnerability has been resolved:

  9p: Fix v9fs_issue_write() to update i_size and remote_i_size

  Fix v9fs_issue_write() to update i_size and remote_i_size to the new size
  of the server file if we made i…
severity: none
vendor: Linux
product: Linux
affected:
  - >-
    Linux >= 5fb70e7275a61dd404f684370e1add7fe0ebe9c5 <
    aeb1fe55583836744aef11fbfa2a09122aa9816c
  - >-
    Linux >= 5fb70e7275a61dd404f684370e1add7fe0ebe9c5 <
    88871ab548c1d7b11cde9b04063f3c1c6fbd7039
  - >-
    Linux >= 5fb70e7275a61dd404f684370e1add7fe0ebe9c5 <
    9cd92e3392bdd14568e9e44aec1ac05e1fcd62e5
  - >-
    Linux >= 5fb70e7275a61dd404f684370e1add7fe0ebe9c5 <
    c60ae98c5aa64021751b38ab1313b19d620bf640
  - Linux 6.10
published: '2026-10-06'
updated: '2026-10-06'
sourceUpdated: '2026-10-06T09:18:16.093'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-98267'
references:
  - url: 'https://git.kernel.org/stable/c/88871ab548c1d7b11cde9b04063f3c1c6fbd7039'
    label: 416baaa9-dc9f-4396-8d5f-8c081fb06d67
  - url: 'https://git.kernel.org/stable/c/9cd92e3392bdd14568e9e44aec1ac05e1fcd62e5'
    label: 416baaa9-dc9f-4396-8d5f-8c081fb06d67
  - url: 'https://git.kernel.org/stable/c/aeb1fe55583836744aef11fbfa2a09122aa9816c'
    label: 416baaa9-dc9f-4396-8d5f-8c081fb06d67
  - url: 'https://git.kernel.org/stable/c/c60ae98c5aa64021751b38ab1313b19d620bf640'
    label: 416baaa9-dc9f-4396-8d5f-8c081fb06d67
tags:
  - nvd
  - cve.org
ingestedAt: '2026-10-06T08:50:17.426Z'
---

## Overview

In the Linux kernel, the following vulnerability has been resolved:

9p: Fix v9fs_issue_write() to update i_size and remote_i_size

Fix v9fs_issue_write() to update i_size and remote_i_size to the new size
of the server file if we made it larger, using the start fpos and the count
returned by p9_client_write() to calculate the new minimum file size.

This assumes that if the 9P server makes a short write (say it hits
ENOSPC), a reduced count is returned.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
