Description
In the Linux kernel, the following vulnerability has been resolved:

f2fs: fix valid block count leak on data block allocation failure

In __allocate_data_block(), when allocating a new data block
(dn->data_blkaddr == NULL_ADDR), inc_valid_block_count() is
called first to increment total_valid_block_count and i_blocks.
If the subsequent f2fs_allocate_data_block() fails, the function
returns the error directly without rolling back the
already-incremented block counts, causing a permanent leak.

Fix this by calling dec_valid_block_count() to undo the
increment before returning the error. The condition
old_blkaddr == NULL_ADDR precisely identifies the case where
inc_valid_block_count() was called.
Published: 2026-09-16
Score: n/a
EPSS: < 1% Very Low
KEV: No
Impact: Integrity of filesystem block counts may be corrupted
Action: Patch Update
AI Analysis

Impact

In the Linux kernel's f2fs filesystem, a bug in __allocate_data_block() caused an undiscounted increment of the total_valid_block_count and i_blocks counters when allocating a data block. If the subsequent allocation step failed, these counts were never subtracted, resulting in a permanent leak of block counters. The effect is a persistent corruption of the filesystem’s block accounting, which can lead to inconsistencies, improper space reporting, or unintended denial of service if many allocation failures accumulate.

Affected Systems

All Linux kernel releases that contain the f2fs filesystem prior to the commit that applied this fix are affected, regardless of vendor. The vulnerability is present in the mainline Linux kernel and therefore applies to any distribution that ships the unpatched kernel binaries.

Risk and Exploitability

The EPSS score of less than 1% and its absence from the CISA KEV catalog suggest that exploitation of this flaw is unlikely. The vulnerability requires a data block allocation failure within the f2fs filesystem, a condition that would generally be local to the host. Because the flaw only causes a permanent increase in the block accounting counters, it could lead to inconsistencies, incorrect space reporting, or a potential denial of service if many allocation failures accumulate, but there is no evidence that an attacker can trigger it remotely.

Generated by OpenCVE AI on September 18, 2026 at 09:36 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade the Linux kernel to a version that includes the f2fs block count leak fix or apply the upstream patch that decrements the counter before returning on error.
  • Reboot the host so the updated kernel is active and the f2fs code path is replaced.
  • Run a filesystem check (fsck.f2fs) against all f2fs partitions to rebuild any corrupted block counts and verify that the block accounting is correct.

Generated by OpenCVE AI on September 18, 2026 at 09:36 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Debian DLA Debian DLA DLA-4817-1 linux-6.12 security update
Debian DSA Debian DSA DSA-6528-1 linux security update
History

Fri, 18 Sep 2026 10:00:00 +0000

Type Values Removed Values Added
Weaknesses CWE-399

Wed, 16 Sep 2026 10:45:00 +0000

Type Values Removed Values Added
Description In the Linux kernel, the following vulnerability has been resolved: f2fs: fix valid block count leak on data block allocation failure In __allocate_data_block(), when allocating a new data block (dn->data_blkaddr == NULL_ADDR), inc_valid_block_count() is called first to increment total_valid_block_count and i_blocks. If the subsequent f2fs_allocate_data_block() fails, the function returns the error directly without rolling back the already-incremented block counts, causing a permanent leak. Fix this by calling dec_valid_block_count() to undo the increment before returning the error. The condition old_blkaddr == NULL_ADDR precisely identifies the case where inc_valid_block_count() was called.
Title f2fs: fix valid block count leak on data block allocation failure
First Time appeared Linux
Linux linux Kernel
CPEs cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
Vendors & Products Linux
Linux linux Kernel
References

Subscriptions

Linux Linux Kernel
cve-icon MITRE

Status: PUBLISHED

Assigner: Linux

Published:

Updated: 2026-09-16T10:31:02.688Z

Reserved: 2026-09-11T19:38:34.769Z

Link: CVE-2026-89830

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-09-16T11:16:49.753

Modified: 2026-09-16T11:16:49.753

Link: CVE-2026-89830

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-18T09:45:06Z

Weaknesses