Impact
A race condition in the f2fs file system allows a concurrent truncate or split operation to shrink or free a large folio after the kernel has dropped its reference. This race results in stale xarray entries and incorrect page state, which can lead to kernel livelocks, bad page statistics, and in extreme cases system crashes. The weakness permits an attacker to destabilize the system by creating conditions that repeatedly trigger the race, causing denial of service.
Affected Systems
Vendors: Linux; Product: Linux kernel with the f2fs file system. The CVE record shows that a v6.18‑based Android system suffered livelock, indicating that kernel versions up to and including 6.18 are affected. Any Linux kernel that includes f2fs but has not yet integrated the patch (commit 0dab71381f1b4d12dc2056f8bd5aaa9d93ce9082 or cc34df18da92f68f9b384c3ae95ad64be46cb5ee) is vulnerable. Systems on unpatched kernels should apply the latest patch or upgrade to a kernel version that incorporates the fix.
Risk and Exploitability
The CVSS score of 7.8 indicates a high severity for stability and availability. The EPSS score of less than 1% suggests that exploitation is unlikely, and the vulnerability is not listed in CISA KEV, implying no known exploitation campaigns. The bug remains present in kernel v6.18 and earlier releases, so systems running those versions are still vulnerable until patched. Likely attack vectors are local or involve file manipulation; the bug requires access to the file system to craft concurrent truncate or split operations. The risk to automated systems is low, but for systems that perform many file operations, the probability of accidental livelock could be significant if the kernel is not patched.
OpenCVE Enrichment