KernelScan.io

CRITICAL

smb FallocateRange OOB

CVE-2026-68388

CVSS 9.8 / 10.0 NVD

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

KernelScan AI8.1HIGH

01

In the Linux kernel, the following vulnerability has been resolved: smb/client: handle overlapping allocated ranges in fallocate smb3_simple_fallocate_range() can skip holes when an allocated range returned by the server starts before the current fallocate offset. The skipped hole is not zero-filled, but fallocate still returns success. A later write to that hole may therefore fail with ENOSPC. The function queries allocated ranges so that it can preserve existing contents and write zeroes only into holes. However, the server may return a range that starts before the current fallocate offset. For example, assume the fallocate request is [100, 400) and the only allocated range returned by the server is [0, 200): Request: [100, 400) Server range: [ 0, 200) allocated Correct: [100, 200) allocated data, skip [200, 400) hole, zero-fill Current: [100, 300) skipped [300, 400) zero-filled afterwards The current code adds the full server range length, 200, to the current offset 100 and moves to 300. As a result, the hole in [200, 300) is skipped without being zero-filled. Fix this by advancing only over the part of the allocated range that overlaps the current fallocate offset. Ignore ranges that end before the current offset and reject ranges whose end offset overflows. This also prevents a malformed range length from causing an out-of-bounds zero-buffer read.

02

Engine v0.6.0

Risk summary

A malicious or compromised SMB server can send crafted allocated-range responses that cause the Linux SMB client to read out-of-bounds from a zero-fill buffer during fallocate, leaking kernel heap memory back to the server. Any local user with write access to a file on an SMB-mounted share can trigger the vulnerable path by calling fallocate; no special privileges are required. The bug also causes holes to be skipped without zero-filling, leading to incorrect file contents and potential ENOSPC failures on later writes.

Affectedfs/smb/client/smb2ops.c (smb client)

Vulnerability analysis

The SMB client's fallocate emulation queries the server for which parts of a file range are already allocated so it can zero-fill only the holes. However, the code did not correctly handle server-returned ranges that start before the current processing position: it advanced the cursor by the full server-reported length instead of only the overlapping portion, skipping holes entirely and leaving them unzeroed. A malformed range length could also cause an out-of-bounds read of the zero-fill buffer, sending kernel heap data back to the server. The fix clamps the cursor advancement to the overlapping part of each range, ignores ranges that end before the current offset, and rejects ranges whose end offset would overflow. Any local user who can call fallocate on a file stored on an SMB share can trigger this; the attacker is the SMB server, which controls the allocated-range responses.

03

BranchIntroducedFixed inPatch commit
5.125.12.175.13017198832355
5.105.10.505.10.265aeb58a4eb39a
5.15—5.15.216437637f5ff3f
6.1—6.1.183377fe3e583e4
6.6—6.6.1487e08ab7a061b
6.12—6.12.101a4a09e514283
6.18—6.18.42b09ae45d85dc
7.1—7.1.6—
mainline—7.2—
5.135.13.25.14f47c7277c03a