Impact
A bug in the Linux f2fs filesystem caused the free_segment_range() routine to fail to evacuate all active curseg types, which can trigger out‑of‑bounds I/O when the filesystem is shrunk. This improper handling can corrupt kernel memory, potentially interleaving writes beyond the truncated storage range and leading to instability or denial of service.
Affected Systems
The issue resides in the Linux kernel's f2fs implementation and affects all kernel releases before the patch that expands the curseg evacuation loop to cover NR_CURSEG_TYPE. Linux kernel users running f2fs filesystems that may be shrunk (e.g., via filesystem resize operations) are impacted.
Risk and Exploitability
The EPSS score of less than 1% indicates the likelihood of exploitation is very low. The vulnerability is not reflected in the CISA KEV catalog. Exploitation would require a privileged or local attacker who can trigger filesystem shrink on an affected f2fs volume, making the risk moderate in environments with privileged local access.
OpenCVE Enrichment
Debian DLA
Debian DSA