Kestrel
대시보드로 돌아가기
CVE-2026-98127UNKNOWNMITRENVD대응게시일: 2026. 09. 25.수정일: 2026. 09. 25.CNA: 416baaa9-dc9f-4396-8d5f-8c081fb06d67Received

In the Linux kernel, the following vulnerability has been resolved: smb/client: validate new EOF for insert range smb3_insert_range() does

위협 신호 · CVSS · EPSS · KEV

정기 패치· 높은 악용 신호 없음
CVSS
—unknown

이론적 심각도 점수

EPSS
—

예측 데이터 없음

KEV
미등재

실측 악용 기록 없음

권장 대응 기한60일 이내CISA SSVC 기준

계획된 패치 주기 내 조치(60일 이내)

외부 노출· KEV 미등재 · 자동화 어려움 · 부분 영향 · 외부 노출

CVSS 벡터 · 메트릭

CVSS 벡터 정보 없음

상세 설명

In the Linux kernel, the following vulnerability has been resolved:

smb/client: validate new EOF for insert range

smb3_insert_range() does not check if the new file size
(i_size + len) is valid. This allows FALLOC_FL_INSERT_RANGE to bypass
RLIMIT_FSIZE, exceed s_maxbytes, or produce a size outside the loff_t
range.

Use check_add_overflow() to calculate the new EOF. Validate it with
inode_newsize_ok() before modifying the file.

Reproducer, using a file on a CIFS mount:

bash
1bash -c '
2 FILE=/mnt/cifs/repro
3
4 trap "" SIGXFSZ
5 ulimit -f 3072 # RLIMIT_FSIZE = 3 MiB
6
7 # A regular write is stopped at 3 MiB.
8 dd if=/dev/zero of="$FILE" bs=1M count=4 status=none
9 stat -c "size after write: %s" "$FILE"
10
11 # Insert 2 MiB into a 2 MiB file.
12 truncate -s 2M "$FILE"
13 fallocate -i -o 0 -l 2M "$FILE"
14 stat -c "size after insert: %s" "$FILE"
15'

Before this change, the regular write stops at the 3 MiB limit, but
insert range grows the file to 4 MiB:

text
1dd: error writing '/mnt/cifs/repro': File too large
2size after write: 3145728
3size after insert: 4194304

After this change, insert range also fails at the limit and leaves the
2 MiB file unchanged:

text
1dd: error writing '/mnt/cifs/repro': File too large
2size after write: 3145728
3fallocate: fallocate failed: File too large
4size after insert: 2097152

AI 심층 분석

공격 시나리오 · 재현 가능한 PoC 페이로드 · 즉시 적용 가능한 차단 패치를 한 번에 받아 보세요. 보안 운영팀이 그대로 점검·티켓팅에 쓸 수 있는 형태로 정리해 드립니다.