CVE-2026-90096

Source
https://cve.org/CVERecord?id=CVE-2026-90096
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-90096.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2026-90096
Downstream
Published
2026-09-17T16:06:08Z
Modified
2026-09-19T03:47:30Z
Summary
fuse: invalidate the correct range after O_APPEND direct write
Details

In the Linux kernel, the following vulnerability has been resolved:

fuse: invalidate the correct range after O_APPEND direct write

fuse_direct_write_iter() captures pos before generic_write_checks(), which moves ki_pos to EOF for O_APPEND writes:

fuse_direct_write_iter() { pos = iocb->ki_pos; /* 0 (user-supplied) / generic_write_checks(); / ki_pos -> EOF / fuse_direct_io(); / writes at EOF, correct / invalidate(pos, pos + res); / [0, res) -- wrong */ }

The post-write invalidation targets a stale range instead of the actual written range at EOF.

This can cause data inconsistency when the file size is not page-aligned. The tail page straddling EOF has a valid portion before EOF that concurrent readers can fault back in during the DIO write window:

Tail page (file size X not page-aligned):

page_start         X (EOF)   page_end
|--- valid data ----|-- stale --|

CPU0 (O_APPEND DIO writer) CPU1 (buffered reader)


invalidate [X, X+len) tail page evicted FUSE_WRITE in flight ... read [page_start, X) tail page re-faulted [X, page_end) = stale FUSE_WRITE completes i_size = X + len invalidate [0, len) <- WRONG tail page still cached read [X, X+len) hits stale tail page returns old data

Fix by reading pos back from iocb->ki_pos after generic_write_checks(), as generic_file_direct_write() does.

Also fix a typo in the comment ("may have" -> "may have competed").

Database specific
{
    "cna_assigner": "Linux",
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/90xxx/CVE-2026-90096.json"
}
References

Affected packages

Git / git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git

Affected ranges

Type
GIT
Repo
https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git
Events
Introduced
2b0408d0284f4ff376cf5610fa8c9905e93c2541
Fixed
833963069adf86dcbdffd4e7d7b3171f95070b77
Fixed
26d7e1f5c407b5859122b5cd47d7ebbf4b4c1cd2

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-90096.json"

Linux / Kernel

Package

Name
Kernel

Affected ranges

Type
ECOSYSTEM
Events
Introduced
7.2.0
Fixed
7.2.6

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-90096.json"