Impact
The bug in the Linux kernel f2fs file system prevents the dirty flag on a node folio from being cleared when a data corruption error is detected. As a result, corrupted metadata can be written to storage, leading to file system corruption and data loss. The weakness can arise when a node block fails a checksum or footer consistency check, causing the node folio to remain dirty until the following persistence operation writes the flawed data.
Affected Systems
The flaw is present in any Linux kernel that uses the f2fs file system. No specific kernel version is listed in the advisory, so the impact potentially spans all recent distributions that compile the standard Linux kernel with f2fs support.
Risk and Exploitability
The CVSS score of 7.8 indicates a high severity, but the EPSS score of less than 1% suggests that exploitation is unlikely at present. The vulnerability is not listed in CISA’s KEV catalog. An attacker would likely need local access or a program running on the affected system to trigger the corruption path; remote exploitation is currently not documented. The consequence is limited to integrity problems and possible service disruption due to corrupted data or filesystem state.
OpenCVE Enrichment