Impact
Based on the description, the flaw is a race condition that can cause the kernel to enter an infinite retry loop while performing f2fs_fsync_node_pages. The race occurs when a thread performs fsync on an f2fs file while another thread modifies the file’s attributes or truncates it. The code path can release a lock and then immediately trigger a retry because atomic && !marked remain true, leading to a deadloop inside the kernel. The resulting denial of service would halt the sync operation and potentially stall the system. This weakness aligns with the CWE‑674 “Uncontrolled Recursion” category, inferred from the infinite looping behavior described.
Affected Systems
The vulnerability impacts all Linux kernel releases that include the f2fs file system implementation and do not yet contain the commit that resolves the deadloop. Vendors that ship a kernel with an unpatched f2fs will be affected; this includes most mainstream Linux distributions as well as custom kernels. The CVE provides no specific version range, so any kernel prior to the patch is potentially vulnerable until the kernel is updated.
Risk and Exploitability
The EPSS score is less than 1 %, indicating a very low probability of exploitation, and the vulnerability is not listed in the CISA KEV catalog. Exploitation would require an attacker to trigger the race condition by performing simultaneous fsync and truncate operations on the same f2fs file, which typically requires elevated privileges or control over file I/O at kernel level. As such, the threat is limited to privileged or malicious insider scenarios; typical unprivileged users cannot exploit the flaw.
OpenCVE Enrichment