Executive brief
The Linux kernel's CIFS (Common Internet File System) implementation contains a cache handling defect in file truncation operations. When files are truncated during open operations, stale cached data can be incorrectly served to applications, potentially exposing sensitive information or causing data consistency issues in systems that rely on network-mounted filesystems.
Technical details
The vulnerability exists in the cifs_do_truncate() function, which is called from cifs_open() without holding the i_rwsem (inode read-write semaphore). The function previously relied on cifs_resize_file_locked() to properly invalidate fscache cookies, but this cannot be safely called without the semaphore. The fix adds an explicit call to cifs_invalidate_cache() after cifs_setsize() to unconditionally invalidate cached data, ensuring stale data is not served from the fscache layer. The flaw impacts all CIFS-mounted network filesystems where files are opened with the O_TRUNC flag (file truncation). The patch has been merged into the Linux kernel mainline and backported to stable kernels.
Affected products
- Linux Linux kernel Affected versions include Linux 5.0 through 6.9 and later; patch released 2026-08-19
Timeline
- 2026-09-11: disclosed: CVE-2026-89639 published
- 2026-08-19: patched: Fix committed to Linux kernel main and stable branches