Impact
The vulnerability lies in the F2FS filesystem implementation of the Linux kernel, where the ioctl F2FS_IOC_MOVE_RANGE accepts a destination range without checking that the extended size stays within bounds. A malicious caller can therefore set a source range that includes a hole (unallocated blocks) and cause the destination inode size to be increased unchecked. This unchecked size calculation permits an integer overflow or size validation failure (CWE‑190) which could lead to kernel memory corruption and a system crash, effectively denying service for the machine. The weakness is an improper size validation that may allow memory corruption when the filesystem is manipulated through this ioctl.
Affected Systems
The affected product is the Linux kernel itself, specifically any kernel that has not yet incorporated the commit that introduces inode_newsize_ok() validation in f2fs. The vendor listing indicates Linux:Linux, but no explicit version range is provided, so all legacy kernels before the fix are impacted. The vulnerability exists regardless of distribution, as the kernel code is common across all implementations that use F2FS.
Risk and Exploitability
The CVSS score is 7.1, indicating moderate severity. The EPSS score is reported as less than 1 %, which suggests a low probability of exploitation at this time. The issue is not listed in the CISA known‑exploited vulnerabilities catalog. Exploitation would require local access to an F2FS‑mounted filesystem and the ability to issue the F2FS_IOC_MOVE_RANGE ioctl. Attackers could trigger this ioctl with crafted parameters and potentially crash the kernel, resulting in a denial‑of‑service condition. No published remote‑exploitation vectors are documented, so the risk to unattended systems is limited but still significant for environments that allow local kernel manipulation or use F2FS in sensitive contexts.
OpenCVE Enrichment