Description
In the Linux kernel, the following vulnerability has been resolved:

f2fs: fix to migrate all curseg types during free_segment_range

In free_segment_range(), the curseg evacuation loop only iterates up to
NR_CURSEG_PERSIST_TYPE (0..5), missing non-persistent in-memory curseg
types such as CURSEG_COLD_DATA_PINNED and CURSEG_ALL_DATA_ATGC.

Even though these in-memory curseg types are not saved in the on-disk
checkpoint header, they still occupy active physical segments at runtime.
If an active in-memory curseg happens to be allocated within the segment
range being truncated during filesystem shrink, failing to evacuate it
will cause subsequent writes to the curseg attempting out-of-bounds I/O
on the truncated storage range.

Fix this by expanding the curseg evacuation loop upper bound to
NR_CURSEG_TYPE to ensure all active curseg types are safely migrated
out of the target range.
Published: 2026-09-16
Score: n/a
EPSS: < 1% Very Low
KEV: No
Impact: Out-of-bounds I/O leading to kernel memory corruption and potential denial of service
Action: Apply Patch
AI Analysis

Impact

A bug in the Linux f2fs filesystem caused the free_segment_range() routine to fail to evacuate all active curseg types, which can trigger out‑of‑bounds I/O when the filesystem is shrunk. This improper handling can corrupt kernel memory, potentially interleaving writes beyond the truncated storage range and leading to instability or denial of service.

Affected Systems

The issue resides in the Linux kernel's f2fs implementation and affects all kernel releases before the patch that expands the curseg evacuation loop to cover NR_CURSEG_TYPE. Linux kernel users running f2fs filesystems that may be shrunk (e.g., via filesystem resize operations) are impacted.

Risk and Exploitability

The EPSS score of less than 1% indicates the likelihood of exploitation is very low. The vulnerability is not reflected in the CISA KEV catalog. Exploitation would require a privileged or local attacker who can trigger filesystem shrink on an affected f2fs volume, making the risk moderate in environments with privileged local access.

Generated by OpenCVE AI on September 18, 2026 at 09:34 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Apply the latest Linux kernel version that incorporates the f2fs curseg evacuation fix (commit 3b85edf3391f3e1f624f409a7d2d239885f567b7 or later), or backport the patch to the current kernel.
  • Until the kernel can be updated, avoid performing filesystem shrink operations on f2fs volumes; if necessary, stop services that may allocate new segments and remount the filesystem as read‑only before shrinking.
  • Restrict filesystem shrink privileges to administrative users only and monitor kernel logs for out-of-bounds I/O errors; consider enforcing SELinux or AppArmor policies that limit f2fs resize capabilities.

Generated by OpenCVE AI on September 18, 2026 at 09:34 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Debian DLA Debian DLA DLA-4817-1 linux-6.12 security update
Debian DSA Debian DSA DSA-6528-1 linux security update
History

Fri, 18 Sep 2026 10:00:00 +0000

Type Values Removed Values Added
Weaknesses CWE-119
CWE-787

Wed, 16 Sep 2026 10:45:00 +0000

Type Values Removed Values Added
Description In the Linux kernel, the following vulnerability has been resolved: f2fs: fix to migrate all curseg types during free_segment_range In free_segment_range(), the curseg evacuation loop only iterates up to NR_CURSEG_PERSIST_TYPE (0..5), missing non-persistent in-memory curseg types such as CURSEG_COLD_DATA_PINNED and CURSEG_ALL_DATA_ATGC. Even though these in-memory curseg types are not saved in the on-disk checkpoint header, they still occupy active physical segments at runtime. If an active in-memory curseg happens to be allocated within the segment range being truncated during filesystem shrink, failing to evacuate it will cause subsequent writes to the curseg attempting out-of-bounds I/O on the truncated storage range. Fix this by expanding the curseg evacuation loop upper bound to NR_CURSEG_TYPE to ensure all active curseg types are safely migrated out of the target range.
Title f2fs: fix to migrate all curseg types during free_segment_range
First Time appeared Linux
Linux linux Kernel
CPEs cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
Vendors & Products Linux
Linux linux Kernel
References

Subscriptions

Linux Linux Kernel
cve-icon MITRE

Status: PUBLISHED

Assigner: Linux

Published:

Updated: 2026-09-16T10:31:07.093Z

Reserved: 2026-09-11T19:38:34.769Z

Link: CVE-2026-89834

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-09-16T11:16:50.180

Modified: 2026-09-16T11:16:50.180

Link: CVE-2026-89834

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-18T09:45:06Z

Weaknesses
  • CWE-119

    Improper Restriction of Operations within the Bounds of a Memory Buffer

  • CWE-787

    Out-of-bounds Write