CVE-2026-98267

high

Description

In the Linux kernel, the following vulnerability has been resolved: 9p: Fix v9fs_issue_write() to update i_size and remote_i_size Fix v9fs_issue_write() to update i_size and remote_i_size to the new size of the server file if we made it larger, using the start fpos and the count returned by p9_client_write() to calculate the new minimum file size. This assumes that if the 9P server makes a short write (say it hits ENOSPC), a reduced count is returned.

References

https://git.kernel.org/stable/c/c60ae98c5aa64021751b38ab1313b19d620bf640

https://git.kernel.org/stable/c/aeb1fe55583836744aef11fbfa2a09122aa9816c

https://git.kernel.org/stable/c/9cd92e3392bdd14568e9e44aec1ac05e1fcd62e5

https://git.kernel.org/stable/c/88871ab548c1d7b11cde9b04063f3c1c6fbd7039

https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-93195

Details

Source: Mitre, NVD

Published: 2026-10-06

Updated: 2026-10-06

Risk Information

CVSS v2

Base Score: 5.6

Vector: CVSS2#AV:L/AC:L/Au:N/C:N/I:P/A:C

Severity: Medium

CVSS v3

Base Score: 7.1

Vector: CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H

Severity: High

EPSS

EPSS: 0.00175