Description
In the Linux kernel, the following vulnerability has been resolved:

f2fs: use the mount idmap for the owner check in f2fs_xattr_advise_set()

f2fs_xattr_advise_set() calls inode_owner_or_capable() with &nop_mnt_idmap
before allowing the "system.advise" xattr to be set, instead of the idmap
that the VFS passes to the ->set() handler.

f2fs supports idmapped mounts, so on such a mount this checks the caller's
fsuid against the unmapped on-disk owner rather than the mapped owner: the
actual owner can be wrongly denied with -EPERM and an unrelated caller
wrongly allowed. Pass the handler's idmap instead.
Published: 2026-09-16
Score: n/a
EPSS: < 1% Very Low
KEV: No
Impact: Unauthorized file attribute manipulation, potential privilege escalation
Action: Immediate Patch
AI Analysis

Impact

An incorrect idmap is used by the f2fs_xattr_advise_set() handler to verify the caller’s ownership when setting a special system.advise extended attribute. Because the mount’s idmap is not applied, a user may be granted permission to set the attribute when they should be denied, or vice versa. This allows an attacker to alter or deny critical file metadata controlled by the root or privileged processes, leading to privilege escalation or corruption of system configuration.

Affected Systems

All Linux kernel installations that use the f2fs file system driver are impacted. The vulnerability exists in the generic f2fs module regardless of kernel release; any system that mounts filesystems using f2fs and allows extended attributes is affected.

Risk and Exploitability

The flaw is an authorization oversight, classified as a CWE‑285 weakness. An attacker with local filesystem access can exploit the vulnerability to create or modify the system.advise attribute. Because the exploit requires local interaction with a mounted f2fs partition, the attack vector is likely local; remote exploitation is unlikely. The EPSS score of <1% indicates a very low probability of widespread public exploitation, and the issue is not listed in the CISA KEV catalog. If patched, the vulnerability is mitigated; until then, unauthorized attribute changes remain possible.

Generated by OpenCVE AI on September 18, 2026 at 08:47 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Apply the latest kernel update that includes the f2fs idmap fix, ensuring the kernel module uses the correct idmap passed by the VFS when checking ownership.
  • If a patch is unavailable, temporarily unmount or disable the f2fs filesystem to prevent the vulnerable attribute operation from being used.
  • Alternatively, limit the use of system.advise extended attributes by applying file ACLs or SELinux/AppArmor policies that restrict who may modify these attributes.

Generated by OpenCVE AI on September 18, 2026 at 08:47 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Debian DLA Debian DLA DLA-4817-1 linux-6.12 security update
Debian DSA Debian DSA DSA-6528-1 linux security update
History

Fri, 18 Sep 2026 09:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-285

Wed, 16 Sep 2026 10:45:00 +0000

Type Values Removed Values Added
Description In the Linux kernel, the following vulnerability has been resolved: f2fs: use the mount idmap for the owner check in f2fs_xattr_advise_set() f2fs_xattr_advise_set() calls inode_owner_or_capable() with &nop_mnt_idmap before allowing the "system.advise" xattr to be set, instead of the idmap that the VFS passes to the ->set() handler. f2fs supports idmapped mounts, so on such a mount this checks the caller's fsuid against the unmapped on-disk owner rather than the mapped owner: the actual owner can be wrongly denied with -EPERM and an unrelated caller wrongly allowed. Pass the handler's idmap instead.
Title f2fs: use the mount idmap for the owner check in f2fs_xattr_advise_set()
First Time appeared Linux
Linux linux Kernel
CPEs cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
Vendors & Products Linux
Linux linux Kernel
References

Subscriptions

Linux Linux Kernel
cve-icon MITRE

Status: PUBLISHED

Assigner: Linux

Published:

Updated: 2026-09-16T10:31:13.727Z

Reserved: 2026-09-11T19:38:34.769Z

Link: CVE-2026-89839

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-09-16T11:16:50.727

Modified: 2026-09-16T11:16:50.727

Link: CVE-2026-89839

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-18T09:00:08Z

Weaknesses