Kernel Vulnerability in Linux Affecting F2FS Compression Feature
CVE-2026-63817

Currently unrated

Key Information:

Vendor

Linux

Status
Vendor
CVE Published:
19 July 2026

What is CVE-2026-63817?

A vulnerability exists in the Linux kernel affecting the F2FS (Flash-Friendly File System) compression feature. When the compress_cache option is disabled, the system fails to properly validate inode numbers associated with compressed page cache inodes, potentially leading to the instantiation of fake internal inodes. This occurs because the inode number treated as a meta inode bypasses necessary range checks. The flaw has been rectified to ensure that such inodes are only validated when the compress_cache option is enabled, thereby preventing out-of-range inode numbers from being accepted.

Affected Version(s)

Linux 6ce19aff0b8cd386860855185c6cd79337fc4d2b < 29115b8c9172d34e67ab26cc4f6c209b7a236d7a

Linux 6ce19aff0b8cd386860855185c6cd79337fc4d2b < 13e4b59d3a9413f66f116fa6c4828519b960a5ea

Linux 6ce19aff0b8cd386860855185c6cd79337fc4d2b < 16161444c30d8dff9428abbae42b72ce4e32a932

References

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.