CVE-2026-89639: Linux

High severity, CVSS 7.1. EPSS: 0.2% chance of exploitation in the next 30 days.

In the Linux kernel, the following vulnerability has been resolved: cifs: use cifs_invalidate_cache() in cifs_do_truncate() for O_TRUNC cifs_do_truncate() is invoked from cifs_open() without i_rwsem, so it cannot use cifs_resize_file_locked() to perform a proper fscache cookie resize. Instead, add cifs_invalidate_cache() after cifs_setsize(). cifs_invalidate_cache() calls fscache_invalidate(), which works without holding i_rwsem: it unconditionally increments inval_counter and sets FSCACHE_COOKIE_NO_DATA_TO_READ, ensuring that stale cached data is not served once the cookie is later activated by fscache_use_cookie(). Truncation to zero leaves no valid cached data, making invalidation the correct semantic here.

Affected products

  • Linux Linux: from 6.18.44, before 6.18.50 (fixed in 6.18.50); from 6.12.105, before 6.13 (fixed in 6.13); from 7.1.8, before 7.2 (fixed in 7.2); from 7.2, before 7.2.4 (fixed in 7.2.4)

Published 2026-09-11. Last modified 2026-09-13.