Operation on a Resource after Expiration or Release in Linux kernel - CVE-2026-98124
Published: September 28, 2026
Vulnerability details
The vulnerability allows a local user to disclose stale file contents.
The vulnerability exists due to improper cache invalidation in FS-Cache handling for SMB client server-side range operations when performing server-side range operations on a file. A local user can perform a server-side range operation and read the affected file to disclose stale file contents.
FS-Cache must be enabled on a CIFS mount with an active CacheFiles backend.