Use of cache containing sensitive information in Linux kernel - CVE-2026-98125
Published: September 28, 2026
Vulnerability details
The vulnerability allows a local user to access stale data.
The vulnerability exists due to improper page-cache invalidation in the SMB client smb3_insert_range() and smb3_collapse_range() functions when performing insert or collapse range operations on files on a CIFS mount. A local user can perform a range operation and read the affected file to access stale data.