Description
In the Linux kernel, the following vulnerability has been resolved:

f2fs: only redirty pinned folios in redirty_blocks

redirty_blocks() pins folios with read_cache_folio() and then walks the
same range again with filemap_lock_folio() to redirty them and drop the
references it took.

Commit 5951fee46bef ("f2fs: Use a folio in redirty_blocks()") changed
the second pass to a do/while loop. If read_cache_folio() fails before
anything is pinned, page_idx does not advance but the cleanup loop still
runs once.

If readahead has already populated the failed folio in page cache, that
extra iteration finds it and folio_put_refs(folio, 2) drops one
reference too many. Later drop_caches or reclaim can then report
"BUG: Bad page state".

Only redirty the range that was pinned successfully.
Published: 2026-09-16
Score: 7.8 High
EPSS: < 1% Very Low
KEV: No
Impact: Kernel memory corruption leading to system crashes
Action: Immediate Patch
AI Analysis

Impact

During a bulk read operation, the kernel incorrectly redirties pages that were not successfully pinned. The readahead mechanism can preload a failed folio, causing an extra iteration in the cleanup loop that decrements the page’s reference count too many times. This mismatch in reference counting can trigger a bad page state and generate a BUG: Bad page state message, which typically leads to a kernel panic or memory corruption, potentially allowing a local attacker to disrupt service or elevate privileges if exploitation can be chained.

Affected Systems

All Linux kernels that use the f2fs filesystem and lack the patch introducing commit 5951fee46bef. Distribution kernel versions prior to the inclusion of this commit are vulnerable; the exact vulnerable releases are not listed but any kernel relying on the pre‑fix f2fs code is affected.

Risk and Exploitability

The CVSS score of 7.8 categorizes this flaw as high severity. With an EPSS score of less than 1% and no listing in the CISA KEV catalog, the risk of exploitation in the wild is currently low. The necessary conditions for exploitation—including local code execution or a compromised system—suggest that the attack vector is likely local, and the impact is denial of service or potential privilege escalation if the attacker can trigger the page fault during active I/O. No public exploit has been reported, and the vulnerability is tied to internal kernel mechanics rather than external interfaces.

Generated by OpenCVE AI on September 18, 2026 at 08:46 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Apply a kernel update that contains commit 5951fee46bef or later, which fixes the reference‑count issue in f2fs.
  • If an immediate distribution update is unavailable, manually apply the patch to the kernel source, rebuild the kernel, and install the new image.
  • Reboot the system after installing the patched kernel to ensure the kernel in use incorporates the fix.

Generated by OpenCVE AI on September 18, 2026 at 08:46 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 18 Sep 2026 09:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-757

Wed, 16 Sep 2026 14:45:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 7.8, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H'}


Wed, 16 Sep 2026 10:45:00 +0000

Type Values Removed Values Added
Description In the Linux kernel, the following vulnerability has been resolved: f2fs: only redirty pinned folios in redirty_blocks redirty_blocks() pins folios with read_cache_folio() and then walks the same range again with filemap_lock_folio() to redirty them and drop the references it took. Commit 5951fee46bef ("f2fs: Use a folio in redirty_blocks()") changed the second pass to a do/while loop. If read_cache_folio() fails before anything is pinned, page_idx does not advance but the cleanup loop still runs once. If readahead has already populated the failed folio in page cache, that extra iteration finds it and folio_put_refs(folio, 2) drops one reference too many. Later drop_caches or reclaim can then report "BUG: Bad page state". Only redirty the range that was pinned successfully.
Title f2fs: only redirty pinned folios in redirty_blocks
First Time appeared Linux
Linux linux Kernel
CPEs cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
Vendors & Products Linux
Linux linux Kernel
References

Subscriptions

Linux Linux Kernel
cve-icon MITRE

Status: PUBLISHED

Assigner: Linux

Published:

Updated: 2026-09-16T14:39:12.019Z

Reserved: 2026-09-11T19:38:34.770Z

Link: CVE-2026-89841

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-09-16T11:16:50.937

Modified: 2026-09-16T15:18:12.597

Link: CVE-2026-89841

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-19T11:45:08Z

Weaknesses
  • CWE-757

    Selection of Less-Secure Algorithm During Negotiation ('Algorithm Downgrade')