CVE-2026-90176
Received
Received - Intake
BaseFortify
Vulnerability report for CVE-2026-90176, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.
Publication date: 2026-09-17
Last updated on: 2026-09-18
Assigner: kernel.org
Description
Description
In the Linux kernel, the following vulnerability has been resolved:
ksmbd: Do not skip lock checks for single-byte ranges
check_lock_range() uses inclusive ranges. Its callers pass the end
offset as start + length - 1, so start == end represents a valid
single-byte range rather than an empty range.
The start == end shortcut therefore skips mandatory byte-range lock
checks for one-byte reads, writes, copychunk operations and one-byte
truncate ranges. A conflicting lock covering that byte is not checked
and the operation is allowed to proceed.
Remove the shortcut. The truncate size == inode->i_size case is already
handled by only calling check_lock_range() when the new size differs
from the current file size.
CVSS Scores
EPSS Scores
| Probability: | |
| Percentile: |
Meta Information
Affected Vendors & Products
| Vendor | Product | Version / Range |
|---|---|---|
| Linux | Linux | 52fcbb92e0d3acfd1448b2a43b6595d540da5295 |
| Linux | Linux | da29cd197246c85c0473259f1cad897d9d28faea |
| Linux | Linux | a6f4cfa3783804336491e0edcb250c25f9b59d33 |
| Linux | Linux | 571204e4758a528fbd67330bd4b0dfbdafb33dd8 |
| Linux | Linux | 5d510ac31626ed157d2182149559430350cf2104 |
| Linux | Linux | 5d510ac31626ed157d2182149559430350cf2104 |
| Linux | Linux | 6.1.160 |
| Linux | Linux | 6.6.120 |
| Linux | Linux | 6.12.64 |
| Linux | Linux | 6.18.3 |
| Linux | Linux | 6.19 |
Helpful Resources
Exploitability
| CWE ID | Description |
|---|---|
| CWE-UNKNOWN |