{
  "affected": [
    {
      "ecosystem_specific": {
        "urgency": "not yet assigned"
      },
      "package": {
        "ecosystem": "Debian:12",
        "name": "linux"
      },
      "ranges": [
        {
          "events": [
            {
              "introduced": "0"
            }
          ],
          "type": "ECOSYSTEM"
        }
      ]
    },
    {
      "ecosystem_specific": {
        "urgency": "not yet assigned"
      },
      "package": {
        "ecosystem": "Debian:13",
        "name": "linux"
      },
      "ranges": [
        {
          "events": [
            {
              "introduced": "0"
            }
          ],
          "type": "ECOSYSTEM"
        }
      ]
    },
    {
      "ecosystem_specific": {
        "urgency": "not yet assigned"
      },
      "package": {
        "ecosystem": "Debian:14",
        "name": "linux"
      },
      "ranges": [
        {
          "events": [
            {
              "introduced": "0"
            }
          ],
          "type": "ECOSYSTEM"
        }
      ]
    }
  ],
  "details": "In the Linux kernel, the following vulnerability has been resolved:  smb/client: invalidate fscache for fallocate range operations  smb3_zero_range(), smb3_punch_hole(), smb3_insert_range(), and smb3_collapse_range() modify file contents through server-side range operations. These operations discard the affected page cache, but leave the FS-Cache cookie valid, so a later read may return data cached before the range operation.  Fix this by invalidating FS-Cache after outstanding I/O has completed and before modifying the file on the server.  Run the following as root on a CIFS mount with fsc enabled and an active CacheFiles backend:          bash -c '                 MNT=/mnt/cifs                 FILE=\"$MNT/repro\"                  # Generate four 1 MiB random blocks: [A][B][C][D].                 dd if=/dev/urandom of=/tmp/src bs=1M count=4 status=none                  # Expected contents after zeroing B: [A][zero][C][D].                 cp /tmp/src /tmp/expected                 dd if=/dev/zero of=/tmp/expected bs=1M seek=1 count=1 \\                         conv=notrunc status=none                 cp /tmp/src \"$FILE\"                  # Populate FS-Cache, then discard the page cache.                 sync                 echo 1 \u003e /proc/sys/vm/drop_caches                 cat \"$FILE\" \u003e /dev/null                 sync                 echo 1 \u003e /proc/sys/vm/drop_caches                  fallocate --zero-range -o 1M -l 1M \"$FILE\"                  if cmp -s /tmp/expected \"$FILE\"; then                         echo \"readback: OK\"                 else                         echo \"readback: STALE DATA\"                 fi         '  Before this change, the readback differs from /tmp/expected:          readback: STALE DATA  After this change, it matches:          readback: OK",
  "id": "DEBIAN-CVE-2026-98124",
  "modified": "2026-09-26T04:47:37.209964572Z",
  "published": "2026-09-25T11:17:43.720Z",
  "references": [
    {
      "type": "ADVISORY",
      "url": "https://security-tracker.debian.org/tracker/CVE-2026-98124"
    }
  ],
  "upstream": [
    "CVE-2026-98124"
  ]
}