CVE-2026-98124

In the Linux kernel, the following vulnerability has been resolved: smb/client: invalidate fscache for fallocate range operations smb3_zero_range(), smb3_punch_hole(), smb3_insert_range(), and smb3_collapse_range() modify file contents through server-side range operations. These operations discard the affected page cache, but leave the FS-Cache cookie valid, so a later read may return data cached before the range operation. Fix this by invalidating FS-Cache after outstanding I/O has completed and before modifying the file on the server. Run the following as root on a CIFS mount with fsc enabled and an active CacheFiles backend: bash -c ' MNT=/mnt/cifs FILE="$MNT/repro" # Generate four 1 MiB random blocks: [A][B][C][D]. dd if=/dev/urandom of=/tmp/src bs=1M count=4 status=none # Expected contents after zeroing B: [A][zero][C][D]. cp /tmp/src /tmp/expected dd if=/dev/zero of=/tmp/expected bs=1M seek=1 count=1 \ conv=notrunc status=none cp /tmp/src "$FILE" # Populate FS-Cache, then discard the page cache. sync echo 1 > /proc/sys/vm/drop_caches cat "$FILE" > /dev/null sync echo 1 > /proc/sys/vm/drop_caches fallocate --zero-range -o 1M -l 1M "$FILE" if cmp -s /tmp/expected "$FILE"; then echo "readback: OK" else echo "readback: STALE DATA" fi ' Before this change, the readback differs from /tmp/expected: readback: STALE DATA After this change, it matches: readback: OK

Package Linux Kernel
Published 2026-09-25
Last modified 2026-09-30
Patch available
Yes

Affected versions

Linux kernel versions 3.17 and later are affected. Fixed in 7.2.7, 7.3-rc2 and their respective stable series.

Affected from
≥ 3.17
Fixed in
✓ 7.2.7 7.2.x ✓ 7.3-rc2

Frequently asked questions

  • What is CVE-2026-98124?

    CVE-2026-98124 is a unscored severity Linux kernel vulnerability . It affects Linux kernel versions from 3.17 onward and has been patched in 7.2.7 and 7.3-rc2. CVE-2026-98124 has not been confirmed as actively exploited and is not listed in the CISA KEV catalog.

  • Is there a patch available for CVE-2026-98124?

    Yes. CVE-2026-98124 has been patched. Fixed versions include 7.2.7 and 7.3-rc2. If you are running Linux kernel 3.17 or later up to the fix versions, apply the relevant patch for your kernel branch.

  • Is CVE-2026-98124 actively exploited?

    No. CVE-2026-98124 has not been confirmed as actively exploited. It is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog.