Impact
The CVE describes a flaw in the f2fs file system driver where a folio reference is not released on an error path in the find_in_block routine, resulting in a kernel memory leak. This defect does not provide an attacker with code execution or privileged access; it only causes the kernel to retain a reference that should be freed, potentially accumulating unused kernel memory. The vulnerability is categorized as a resource‑leak flaw.
Affected Systems
All Linux operating system images that use the f2fs file system and include a kernel version that has not yet been patched for this flaw are affected. The documentation does not list specific kernel release numbers, so any legacy kernel deployed in F2FS‑enabled environments is potentially vulnerable until the fix is applied.
Risk and Exploitability
The EPSS score of less than 1% indicates that exploitation of this flaw is unlikely. The vulnerability is not listed in the CISA KEV catalog. The flaw involves a reference leak and does not provide a direct path to privilege escalation or code execution. The effect is a potential memory leak that could, over time, consume kernel memory, but it does not grant an attacker immediate capabilities.
OpenCVE Enrichment