CVE-2026-98127 Affecting linux-6.12 package, versions <6.12.111-1~deb12u1


Severity

Recommended
low

Based on default assessment until relevant scores are available.

Threat Intelligence

EPSS
0.18% (7th percentile)

Do your applications use this vulnerable package?

In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.

Test your applications
  • Snyk IDSNYK-DEBIAN12-LINUX612-20506521
  • published5 Oct 2026
  • disclosed25 Sept 2026

Introduced: 25 Sep 2026

NewCVE-2026-98127  (opens in a new tab)

How to fix?

Upgrade Debian:12 linux-6.12 to version 6.12.111-1~deb12u1 or higher.

NVD Description

Note: Versions mentioned in the description apply only to the upstream linux-6.12 package and not the linux-6.12 package as distributed by Debian. See How to fix? for Debian:12 relevant fixed versions and status.

In the Linux kernel, the following vulnerability has been resolved:

smb/client: validate new EOF for insert range

smb3_insert_range() does not check if the new file size (i_size + len) is valid. This allows FALLOC_FL_INSERT_RANGE to bypass RLIMIT_FSIZE, exceed s_maxbytes, or produce a size outside the loff_t range.

Use check_add_overflow() to calculate the new EOF. Validate it with inode_newsize_ok() before modifying the file.

Reproducer, using a file on a CIFS mount:

bash -c &#39;
    FILE=/mnt/cifs/repro

trap &amp;#34;&amp;#34; SIGXFSZ
ulimit -f 3072		# RLIMIT_FSIZE = 3 MiB

# A regular write is stopped at 3 MiB.
dd if=/dev/zero of=&amp;#34;$FILE&amp;#34; bs=1M count=4 status=none
stat -c &amp;#34;size after write: %s&amp;#34; &amp;#34;$FILE&amp;#34;

# Insert 2 MiB into a 2 MiB file.
truncate -s 2M &amp;#34;$FILE&amp;#34;
fallocate -i -o 0 -l 2M &amp;#34;$FILE&amp;#34;
stat -c &amp;#34;size after insert: %s&amp;#34; &amp;#34;$FILE&amp;#34;

&#39;

Before this change, the regular write stops at the 3 MiB limit, but insert range grows the file to 4 MiB:

dd: error writing &#39;/mnt/cifs/repro&#39;: File too large
size after write: 3145728
size after insert: 4194304

After this change, insert range also fails at the limit and leaves the 2 MiB file unchanged:

dd: error writing &#39;/mnt/cifs/repro&#39;: File too large
size after write: 3145728
fallocate: fallocate failed: File too large
size after insert: 2097152

CVSS Base Scores

version 3.1