CVE-2026-68388 affects smb3_simple_fallocate_range() in the Linux kernel SMB client. The function queries server-reported allocated ranges to preserve existing data and zero-fill holes during fallocate. When a returned range begins before the current allocation offset, the vulnerable implementation advances by the entire range length rather than the remaining overlapping portion. This can skip holes without zero-filling them while fallocate reports success, potentially causing subsequent writes to fail with ENOSPC. Malformed range lengths can also cause an out-of-bounds read from the zero buffer.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
No public exploits tracked yet. Mallory keeps watching.
No public exploit code observed for this vulnerability.
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
31 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Incorrect handling of overlapping allocated ranges in fallocate within the Linux kernel SMB client. The content does not specify the precise security impact.
A Linux kernel SMB client flaw incorrectly handles overlapping server-reported allocated ranges during fallocate operations. It can leave holes without zero-filling while reporting success, causing later writes to fail with ENOSPC. Malformed range lengths can also cause an out-of-bounds zero-buffer read. The advisory recommends updating affected Google COS kernel packages to version 18867.584.3 or later.
A Linux kernel SMB client vulnerability involving incorrect handling of overlapping allocated ranges during fallocate operations. The flaw can leave holes without zero-filling despite reporting success, potentially causing subsequent writes to fail with ENOSPC. Malformed range lengths can also cause an out-of-bounds zero-buffer read. The plugin rates the vulnerability critical with CVSS v3 9.8, while the vendor severity is LOW.
A Linux kernel SMB client vulnerability involving incorrect handling of overlapping server-reported allocated ranges during fallocate operations. Incorrect offset calculations can leave holes without zero-filling despite reporting success, potentially causing subsequent writes to fail with ENOSPC. Malformed range lengths can also cause an out-of-bounds zero-buffer read. The reference assigns a CVSS v3 base score of 9.8, while the vendor rates severity LOW.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.