Description
In the Linux kernel, the following vulnerability has been resolved:

f2fs: fix dentry folio leak in find_in_level

find_in_level() gets a dentry folio with f2fs_find_data_folio() before
calling find_in_block(). If find_in_block() returns an error, the
function stores the error in res_folio and breaks out of the loop without
dropping the dentry folio.

This leaks the folio reference on the find_in_block() error path. Drop
the dentry folio before returning the error to the caller.
Published: 2026-09-16
Score: n/a
EPSS: < 1% Very Low
KEV: No
Impact: Resource Leak
Action: Apply Patch
AI Analysis

Impact

The CVE describes a flaw in the f2fs file system driver where a folio reference is not released on an error path in the find_in_block routine, resulting in a kernel memory leak. This defect does not provide an attacker with code execution or privileged access; it only causes the kernel to retain a reference that should be freed, potentially accumulating unused kernel memory. The vulnerability is categorized as a resource‑leak flaw.

Affected Systems

All Linux operating system images that use the f2fs file system and include a kernel version that has not yet been patched for this flaw are affected. The documentation does not list specific kernel release numbers, so any legacy kernel deployed in F2FS‑enabled environments is potentially vulnerable until the fix is applied.

Risk and Exploitability

The EPSS score of less than 1% indicates that exploitation of this flaw is unlikely. The vulnerability is not listed in the CISA KEV catalog. The flaw involves a reference leak and does not provide a direct path to privilege escalation or code execution. The effect is a potential memory leak that could, over time, consume kernel memory, but it does not grant an attacker immediate capabilities.

Generated by OpenCVE AI on September 18, 2026 at 09:32 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Update the Linux kernel to a revision that incorporates the patch referenced by the commit hash 93a3e6a4c9e726a13a935963e8dc43d181db1527 or later. In most distributions this means installing the latest security‑updated kernel package or applying the vendor’s patch set.
  • If an immediate package update is not available, manually apply the patch to the kernel source tree, rebuild the kernel, and install the new image.
  • Reboot the system after installing the patched kernel to ensure all memory references are released and the new folio handling logic is active.

Generated by OpenCVE AI on September 18, 2026 at 09:32 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sat, 03 Oct 2026 11:15:00 +0000


Fri, 18 Sep 2026 10:00:00 +0000

Type Values Removed Values Added
Weaknesses CWE-459

Wed, 16 Sep 2026 10:45:00 +0000

Type Values Removed Values Added
Description In the Linux kernel, the following vulnerability has been resolved: f2fs: fix dentry folio leak in find_in_level find_in_level() gets a dentry folio with f2fs_find_data_folio() before calling find_in_block(). If find_in_block() returns an error, the function stores the error in res_folio and breaks out of the loop without dropping the dentry folio. This leaks the folio reference on the find_in_block() error path. Drop the dentry folio before returning the error to the caller.
Title f2fs: fix dentry folio leak in find_in_level
First Time appeared Linux
Linux linux Kernel
CPEs cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
Vendors & Products Linux
Linux linux Kernel
References

Subscriptions

Linux Linux Kernel
cve-icon MITRE

Status: PUBLISHED

Assigner: Linux

Published:

Updated: 2026-10-03T10:56:45.631Z

Reserved: 2026-09-11T19:38:34.769Z

Link: CVE-2026-89837

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-09-16T11:16:50.513

Modified: 2026-10-03T11:17:44.200

Link: CVE-2026-89837

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-18T09:45:06Z

Weaknesses