Impact
In the Linux kernel’s f2fs filesystem, the function f2fs_sanity_check_node_footer() mistakenly compares the same node identifier (nid) instead of using the folio->index value. This logic error can allow a privileged attacker to bypass node integrity checks, potentially corrupting file data or rendering the filesystem into an inconsistent state. The resulting impact threatens the confidentiality and integrity of data stored on f2fs mounts and may lead to a denial of service if corrupted nodes prevent proper filesystem operation.
Affected Systems
The flaw affects all Linux kernel releases that include the f2fs filesystem component. Kernel builds prior to the patch commit listed in the advisory are considered vulnerable; no specific minor or patch levels are excluded.
Risk and Exploitability
The CVSS score of 7.8 indicates a high severity vulnerability. The EPSS score of less than 1% suggests a very low probability of exploitation in the wild, and it is not listed in the CISA KEV catalog. Based on the description, the likely attack vector is local, requiring the attacker to have kernel‑level or root access to trigger the faulty sanity check. The exploit could result in filesystem corruption or denial of service. It is not confirmed whether a public proof‑of‑concept exists, but the logic flaw appears straightforward for a skilled attacker with sufficient privileges.
OpenCVE Enrichment