CVE-2026-89840

🟡 Monitoruj

Błąd w F2FS pozwala na niekontrolowane rozszerzenie rozmiaru inodów, co może prowadzić do uszkodzenia danych.

CVSS
7.1
EPSS
0.2%
Exploit
none
Vendor
Opis źródłowy (NVD)

In the Linux kernel, the following vulnerability has been resolved: f2fs: validate MOVE_RANGE destination size F2FS_IOC_MOVE_RANGE checks the source range, but not the destination end before updating i_size. A source hole can expose this: __clone_blkaddrs() skips NULL_ADDR entries and returns success, so the caller can still extend the destination inode with unchecked pos_out + len. Reject destination overflow and use inode_newsize_ok() before extending the destination inode.

brak Brak patcha
Źródła i daty
ŹródłoWartość
NVD – CVSS7.1
CISA KEV (aktywnie wykorzystywane)Nie
FIRST EPSS (prawdopodobieństwo exploita)0.2%
Opublikowano (NVD)2026-09-16 11:16:50 UTC
Ostatnia modyfikacja (NVD)2026-10-03 11:17:44 UTC
Referencje