Description
In the Linux kernel, the following vulnerability has been resolved:

f2fs: fix to pass folio->index to f2fs_sanity_check_node_footer()

Otherwise in f2fs_sanity_check_node_footer(), it will check the
same nid incorrectly.
Published: 2026-09-16
Score: 7.8 High
EPSS: < 1% Very Low
KEV: No
Impact: Filesystem integrity compromise due to improper node index check
Action: Apply patch
AI Analysis

Impact

In the Linux kernel’s f2fs filesystem, the function f2fs_sanity_check_node_footer() mistakenly compares the same node identifier (nid) instead of using the folio->index value. This logic error can allow a privileged attacker to bypass node integrity checks, potentially corrupting file data or rendering the filesystem into an inconsistent state. The resulting impact threatens the confidentiality and integrity of data stored on f2fs mounts and may lead to a denial of service if corrupted nodes prevent proper filesystem operation.

Affected Systems

The flaw affects all Linux kernel releases that include the f2fs filesystem component. Kernel builds prior to the patch commit listed in the advisory are considered vulnerable; no specific minor or patch levels are excluded.

Risk and Exploitability

The CVSS score of 7.8 indicates a high severity vulnerability. The EPSS score of less than 1% suggests a very low probability of exploitation in the wild, and it is not listed in the CISA KEV catalog. Based on the description, the likely attack vector is local, requiring the attacker to have kernel‑level or root access to trigger the faulty sanity check. The exploit could result in filesystem corruption or denial of service. It is not confirmed whether a public proof‑of‑concept exists, but the logic flaw appears straightforward for a skilled attacker with sufficient privileges.

Generated by OpenCVE AI on September 18, 2026 at 09:36 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Update the Linux kernel to a release that contains the f2fs index‑check patch from the referenced commits.
  • If an immediate kernel upgrade is not possible, unmount or migrate any f2fs mounts to prevent further use until the patch is applied.
  • Apply the kernel patch manually by cherry‑looking or patching with the provided diff and rebuild the kernel. After patching, run fsck.f2fs on existing mounts to detect and repair any corruption.

Generated by OpenCVE AI on September 18, 2026 at 09:36 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 18 Sep 2026 10:00:00 +0000

Type Values Removed Values Added
Weaknesses CWE-665
CWE-751

Wed, 16 Sep 2026 14:45:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 7.8, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H'}


Wed, 16 Sep 2026 10:45:00 +0000

Type Values Removed Values Added
Description In the Linux kernel, the following vulnerability has been resolved: f2fs: fix to pass folio->index to f2fs_sanity_check_node_footer() Otherwise in f2fs_sanity_check_node_footer(), it will check the same nid incorrectly.
Title f2fs: fix to pass folio->index to f2fs_sanity_check_node_footer()
First Time appeared Linux
Linux linux Kernel
CPEs cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
Vendors & Products Linux
Linux linux Kernel
References

Subscriptions

Linux Linux Kernel
cve-icon MITRE

Status: PUBLISHED

Assigner: Linux

Published:

Updated: 2026-09-16T14:39:05.836Z

Reserved: 2026-09-11T19:38:34.769Z

Link: CVE-2026-89829

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-09-16T11:16:49.620

Modified: 2026-09-16T15:18:11.667

Link: CVE-2026-89829

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-18T09:45:06Z

Weaknesses