Impact
During a bulk read operation, the kernel incorrectly redirties pages that were not successfully pinned. The readahead mechanism can preload a failed folio, causing an extra iteration in the cleanup loop that decrements the page’s reference count too many times. This mismatch in reference counting can trigger a bad page state and generate a BUG: Bad page state message, which typically leads to a kernel panic or memory corruption, potentially allowing a local attacker to disrupt service or elevate privileges if exploitation can be chained.
Affected Systems
All Linux kernels that use the f2fs filesystem and lack the patch introducing commit 5951fee46bef. Distribution kernel versions prior to the inclusion of this commit are vulnerable; the exact vulnerable releases are not listed but any kernel relying on the pre‑fix f2fs code is affected.
Risk and Exploitability
The CVSS score of 7.8 categorizes this flaw as high severity. With an EPSS score of less than 1% and no listing in the CISA KEV catalog, the risk of exploitation in the wild is currently low. The necessary conditions for exploitation—including local code execution or a compromised system—suggest that the attack vector is likely local, and the impact is denial of service or potential privilege escalation if the attacker can trigger the page fault during active I/O. No public exploit has been reported, and the vulnerability is tied to internal kernel mechanics rather than external interfaces.
OpenCVE Enrichment