Description
In the Linux kernel, the following vulnerability has been resolved:

f2fs: fix to avoid potential deadloop in f2fs_fsync_node_pages()

There is potential deadloop in race condition:

Thread A Thread B
- fsync
- f2fs_do_sync_file
- f2fs_fsync_node_pages
- last_fsync_dnode
- folio_get(last_folio)
- f2fs_setattr
- f2fs_truncate
- f2fs_truncate_blocks
- f2fs_do_truncate_blocks
- f2fs_truncate_inode_blocks
- truncate_dnode
- truncate_node
- invalidate_mapping_pages
- folio->mapping = NULL
- is_node_folio alwasy return false
- atomic && !marked is always true,
then goto retry
Published: 2026-09-16
Score: n/a
EPSS: < 1% Very Low
KEV: No
Impact: Denial of Service via kernel deadloop
Action: Patch immediately
AI Analysis

Impact

Based on the description, the flaw is a race condition that can cause the kernel to enter an infinite retry loop while performing f2fs_fsync_node_pages. The race occurs when a thread performs fsync on an f2fs file while another thread modifies the file’s attributes or truncates it. The code path can release a lock and then immediately trigger a retry because atomic && !marked remain true, leading to a deadloop inside the kernel. The resulting denial of service would halt the sync operation and potentially stall the system. This weakness aligns with the CWE‑674 “Uncontrolled Recursion” category, inferred from the infinite looping behavior described.

Affected Systems

The vulnerability impacts all Linux kernel releases that include the f2fs file system implementation and do not yet contain the commit that resolves the deadloop. Vendors that ship a kernel with an unpatched f2fs will be affected; this includes most mainstream Linux distributions as well as custom kernels. The CVE provides no specific version range, so any kernel prior to the patch is potentially vulnerable until the kernel is updated.

Risk and Exploitability

The EPSS score is less than 1 %, indicating a very low probability of exploitation, and the vulnerability is not listed in the CISA KEV catalog. Exploitation would require an attacker to trigger the race condition by performing simultaneous fsync and truncate operations on the same f2fs file, which typically requires elevated privileges or control over file I/O at kernel level. As such, the threat is limited to privileged or malicious insider scenarios; typical unprivileged users cannot exploit the flaw.

Generated by OpenCVE AI on September 18, 2026 at 09:54 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Update the Linux kernel to a release that includes the f2fs_fsync_node_pages fix (commit 161513f53e4ac90fd356433bdf8e31e6adeb92af or later).
  • Reboot the system after installing the updated kernel to ensure the patched code is loaded.
  • As a temporary mitigation, avoid concurrent fsync and truncate operations on f2fs or migrate critical workloads to a more stable filesystem such as ext4; if immediate migration is not possible, consider mounting the f2fs partition read‑only during periods of heavy filesystem activity.

Generated by OpenCVE AI on September 18, 2026 at 09:54 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 18 Sep 2026 10:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-674

Wed, 16 Sep 2026 10:45:00 +0000

Type Values Removed Values Added
Description In the Linux kernel, the following vulnerability has been resolved: f2fs: fix to avoid potential deadloop in f2fs_fsync_node_pages() There is potential deadloop in race condition: Thread A Thread B - fsync - f2fs_do_sync_file - f2fs_fsync_node_pages - last_fsync_dnode - folio_get(last_folio) - f2fs_setattr - f2fs_truncate - f2fs_truncate_blocks - f2fs_do_truncate_blocks - f2fs_truncate_inode_blocks - truncate_dnode - truncate_node - invalidate_mapping_pages - folio->mapping = NULL - is_node_folio alwasy return false - atomic && !marked is always true, then goto retry
Title f2fs: fix to avoid potential deadloop in f2fs_fsync_node_pages()
First Time appeared Linux
Linux linux Kernel
CPEs cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
Vendors & Products Linux
Linux linux Kernel
References

Subscriptions

Linux Linux Kernel
cve-icon MITRE

Status: PUBLISHED

Assigner: Linux

Published:

Updated: 2026-09-16T10:31:05.680Z

Reserved: 2026-09-11T19:38:34.769Z

Link: CVE-2026-89833

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-09-16T11:16:50.080

Modified: 2026-09-16T11:16:50.080

Link: CVE-2026-89833

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-18T10:00:06Z

Weaknesses