Impact
In the Linux kernel's f2fs filesystem, a bug in __allocate_data_block() caused an undiscounted increment of the total_valid_block_count and i_blocks counters when allocating a data block. If the subsequent allocation step failed, these counts were never subtracted, resulting in a permanent leak of block counters. The effect is a persistent corruption of the filesystem’s block accounting, which can lead to inconsistencies, improper space reporting, or unintended denial of service if many allocation failures accumulate.
Affected Systems
All Linux kernel releases that contain the f2fs filesystem prior to the commit that applied this fix are affected, regardless of vendor. The vulnerability is present in the mainline Linux kernel and therefore applies to any distribution that ships the unpatched kernel binaries.
Risk and Exploitability
The EPSS score of less than 1% and its absence from the CISA KEV catalog suggest that exploitation of this flaw is unlikely. The vulnerability requires a data block allocation failure within the f2fs filesystem, a condition that would generally be local to the host. Because the flaw only causes a permanent increase in the block accounting counters, it could lead to inconsistencies, incorrect space reporting, or a potential denial of service if many allocation failures accumulate, but there is no evidence that an attacker can trigger it remotely.
OpenCVE Enrichment
Debian DLA
Debian DSA