Race condition in Linux kernel - CVE-2026-93794
Published: September 25, 2026
Vulnerability details
The vulnerability allows a local user to cause punched file ranges to be incorrectly reported as allocated data.
The vulnerability exists due to improper synchronization in the SMB client smb3_punch_hole function when punching a hole after a large buffered write. A local user can perform a large buffered write followed by a hole-punch operation to cause punched file ranges to be incorrectly reported as allocated data.