Impact
The vulnerability occurs in the Linux kernel’s F2FS filesystem. It allows the kernel to log recovery filenames from a non‑NUL terminated buffer using the %s format specifier, causing the log operation to read beyond the intended string and potentially expose internal inode data. This can lead to an information disclosure to an attacker with access to system logs, as the weakness involves an improper handling of a non‑terminated string and a bounded overread beyond the buffer limits.
Affected Systems
The flaw affects all Linux operating systems that use the Linux kernel with the F2FS filesystem. It is present in kernel versions prior to the latest f2fs patch. Kernel vendors: Linux (generic).
Risk and Exploitability
The CVSS score is 7.1, indicating a moderate to high risk. The EPSS score is less than 1%, suggesting low exploitation probability. The vulnerability is not listed in the CISA KEV catalog. The attack likely requires local access or privileged exposure to the kernel logs; an attacker would need to obtain read access to kernel logs or influence the system to trigger recovery logging, making the threat level moderate.
OpenCVE Enrichment