# CVE-2026-89640

## Summary

- **CVE ID:** CVE-2026-89640
- **Severity:** HIGH
- **CVSS Score:** 7.1 (CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H)
- **CWE:** N/A
- **Published:** Sep 11, 2026
- **Last Modified:** Sep 14, 2026

## Description

In the Linux kernel, the following vulnerability has been resolved:

cifs: fix loff_t underflow in cifs_remap_file_range() when len == 0

With len == 0 (clone to EOF), the effective length is computed as:

    len = src_inode->i_size - off;

If off > i_size, this is a negative loff_t, corrupting the ByteCount
in the FSCTL_DUPLICATE_EXTENTS_TO_FILE request and inverting the range
in filemap_write_and_wait_range().  The existing off >= i_size check
fires only after the ioctl has already been sent.

Snapshot i_size_read() once for both the bounds check and the length
calculation, eliminating the TOCTOU and 32-bit torn-read risk.  Reject
off > src_size with -EINVAL.  Treat off == src_size as a no-op,
consistent with __generic_remap_file_range_prep().

## Affected Products

- Linux — Linux (04b38d601239b4d9be641b412cf4b7456a041c67)
- Linux — Linux (4.5)
- Linux — Linux (0)
- Linux — Linux (6.12.109)
- Linux — Linux (6.18.50)
- Linux — Linux (7.2.4)
- Linux — Linux (7.3-rc1)
- Linux — Linux (6.1.188)
- Linux — Linux (6.6.157)

## References

- [CNA](https://git.kernel.org/stable/c/b098f5e5858797827666e6cd73033f52fc39b5f6)
- [CNA](https://git.kernel.org/stable/c/c2a0dcb5a7a1516aa6eb6d5cedca6a8e76527028)
- [CNA](https://git.kernel.org/stable/c/b057ca17b656345d04669cb87f2aff9b31d873db)
- [CNA](https://git.kernel.org/stable/c/6c322f5cf7476ded7a9a20f7be72462065a03c68)
- [CNA](https://git.kernel.org/stable/c/f3d1ae1e6bc4a9f559185b6e7bd2b6375ec2fdd4)
- [CNA](https://git.kernel.org/stable/c/7f62817fe049b0f3652518c1ba72631ec1e0a322)

## Exploitation Prediction (EPSS)

- **EPSS Score:** 0.13%
- **EPSS Percentile:** 2.6

---
_Exported from OnDuty AI Vulnerability Intelligence on 2026-09-18._