Kernel Vulnerability in Linux Affecting F2FS Compression Feature
CVE-2026-63817
What is CVE-2026-63817?
A vulnerability exists in the Linux kernel affecting the F2FS (Flash-Friendly File System) compression feature. When the compress_cache option is disabled, the system fails to properly validate inode numbers associated with compressed page cache inodes, potentially leading to the instantiation of fake internal inodes. This occurs because the inode number treated as a meta inode bypasses necessary range checks. The flaw has been rectified to ensure that such inodes are only validated when the compress_cache option is enabled, thereby preventing out-of-range inode numbers from being accepted.
Affected Version(s)
Linux 6ce19aff0b8cd386860855185c6cd79337fc4d2b < 29115b8c9172d34e67ab26cc4f6c209b7a236d7a
Linux 6ce19aff0b8cd386860855185c6cd79337fc4d2b < 13e4b59d3a9413f66f116fa6c4828519b960a5ea
Linux 6ce19aff0b8cd386860855185c6cd79337fc4d2b < 16161444c30d8dff9428abbae42b72ce4e32a932