Vulnerability in Linux Kernel Affecting F2FS File System by Vendor
CVE-2026-63811

Currently unrated

Key Information:

Vendor

Linux

Status
Vendor
CVE Published:
19 July 2026

What is CVE-2026-63811?

The Linux kernel has a notable vulnerability in the F2FS file system that relates to atomic writes and Copy-On-Write (COW) data management. When an atomic-write file is updated, the mechanism used to read data from a COW inode may inadvertently access unencrypted data from the original inode, resulting in a general protection fault due to a null pointer dereference. This occurs because encryption policies associated with COW inodes do not align correctly with those of the original files, leading to significant data handling issues. The flaw necessitates architectural adjustments within the F2FS functions to ensure proper encryption context handling and maintain data integrity during read operations.

Affected Version(s)

Linux 591fc34e1f98b0d7eef4aa3440bfdff3c5a1cadd

Linux 591fc34e1f98b0d7eef4aa3440bfdff3c5a1cadd

Linux 6.4

References

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.