Description
In the Linux kernel, the following vulnerability has been resolved:

f2fs: validate MOVE_RANGE destination size

F2FS_IOC_MOVE_RANGE checks the source range, but not the destination end
before updating i_size. A source hole can expose this: __clone_blkaddrs()
skips NULL_ADDR entries and returns success, so the caller can still extend
the destination inode with unchecked pos_out + len.

Reject destination overflow and use inode_newsize_ok() before extending
the destination inode.
Published: 2026-09-16
Score: 7.1 High
EPSS: < 1% Very Low
KEV: No
Impact: Denial of Service (kernel crash)
Action: Patch
AI Analysis

Impact

The vulnerability lies in the F2FS filesystem implementation of the Linux kernel, where the ioctl F2FS_IOC_MOVE_RANGE accepts a destination range without checking that the extended size stays within bounds. A malicious caller can therefore set a source range that includes a hole (unallocated blocks) and cause the destination inode size to be increased unchecked. This unchecked size calculation permits an integer overflow or size validation failure (CWE‑190) which could lead to kernel memory corruption and a system crash, effectively denying service for the machine. The weakness is an improper size validation that may allow memory corruption when the filesystem is manipulated through this ioctl.

Affected Systems

The affected product is the Linux kernel itself, specifically any kernel that has not yet incorporated the commit that introduces inode_newsize_ok() validation in f2fs. The vendor listing indicates Linux:Linux, but no explicit version range is provided, so all legacy kernels before the fix are impacted. The vulnerability exists regardless of distribution, as the kernel code is common across all implementations that use F2FS.

Risk and Exploitability

The CVSS score is 7.1, indicating moderate severity. The EPSS score is reported as less than 1 %, which suggests a low probability of exploitation at this time. The issue is not listed in the CISA known‑exploited vulnerabilities catalog. Exploitation would require local access to an F2FS‑mounted filesystem and the ability to issue the F2FS_IOC_MOVE_RANGE ioctl. Attackers could trigger this ioctl with crafted parameters and potentially crash the kernel, resulting in a denial‑of‑service condition. No published remote‑exploitation vectors are documented, so the risk to unattended systems is limited but still significant for environments that allow local kernel manipulation or use F2FS in sensitive contexts.

Generated by OpenCVE AI on September 18, 2026 at 08:47 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Apply the latest stable Linux kernel that includes the commit fixing the f2fs move‑range destination size validation. This is the official vendor recommended fix.
  • If an immediate kernel upgrade is not possible, restrict or remove the ability to use the F2FS_IOC_MOVE_RANGE ioctl from non‑trusted users by adjusting filesystem or system policy, or unmount the affected F2FS partitions until a patch can be applied.
  • As an additional safeguard, audit and patch any scripts or programs that call F2FS_IOC_MOVE_RANGE to ensure they operate only on valid ranges or post‑patch kernels, and monitor kernel logs for OOPS events that could indicate a related issue.

Generated by OpenCVE AI on September 18, 2026 at 08:47 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sat, 03 Oct 2026 11:15:00 +0000


Mon, 21 Sep 2026 13:30:00 +0000


Fri, 18 Sep 2026 09:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-190

Wed, 16 Sep 2026 14:45:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 7.1, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H'}


Wed, 16 Sep 2026 10:45:00 +0000

Type Values Removed Values Added
Description In the Linux kernel, the following vulnerability has been resolved: f2fs: validate MOVE_RANGE destination size F2FS_IOC_MOVE_RANGE checks the source range, but not the destination end before updating i_size. A source hole can expose this: __clone_blkaddrs() skips NULL_ADDR entries and returns success, so the caller can still extend the destination inode with unchecked pos_out + len. Reject destination overflow and use inode_newsize_ok() before extending the destination inode.
Title f2fs: validate MOVE_RANGE destination size
First Time appeared Linux
Linux linux Kernel
CPEs cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
Vendors & Products Linux
Linux linux Kernel
References

Subscriptions

Linux Linux Kernel
cve-icon MITRE

Status: PUBLISHED

Assigner: Linux

Published:

Updated: 2026-10-03T10:56:48.043Z

Reserved: 2026-09-11T19:38:34.769Z

Link: CVE-2026-89840

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-09-16T11:16:50.837

Modified: 2026-10-03T11:17:44.437

Link: CVE-2026-89840

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-18T09:00:08Z

Weaknesses
  • CWE-190

    Integer Overflow or Wraparound