Impact
An incorrect idmap is used by the f2fs_xattr_advise_set() handler to verify the caller’s ownership when setting a special system.advise extended attribute. Because the mount’s idmap is not applied, a user may be granted permission to set the attribute when they should be denied, or vice versa. This allows an attacker to alter or deny critical file metadata controlled by the root or privileged processes, leading to privilege escalation or corruption of system configuration.
Affected Systems
All Linux kernel installations that use the f2fs file system driver are impacted. The vulnerability exists in the generic f2fs module regardless of kernel release; any system that mounts filesystems using f2fs and allows extended attributes is affected.
Risk and Exploitability
The flaw is an authorization oversight, classified as a CWE‑285 weakness. An attacker with local filesystem access can exploit the vulnerability to create or modify the system.advise attribute. Because the exploit requires local interaction with a mounted f2fs partition, the attack vector is likely local; remote exploitation is unlikely. The EPSS score of <1% indicates a very low probability of widespread public exploitation, and the issue is not listed in the CISA KEV catalog. If patched, the vulnerability is mitigated; until then, unauthorized attribute changes remain possible.
OpenCVE Enrichment
Debian DLA
Debian DSA