Linux Kernel Vulnerability Affecting F2FS File System by Linux Foundation
CVE-2026-63818
What is CVE-2026-63818?
A flaw in the Linux kernel's f2fs module allows for improper validation of orphan inode entry counts. When replaying orphan inodes from the checkpoint pack, a corrupted entry count can cause the system to read beyond the ino[] array, potentially interpreting unrelated data as inode numbers. This misrepresents the orphan recovery process and may lead to a kernel panic. The recommended fix includes validating the entry count prior to consumption, ensuring that corrupted data results in an error state that prompts a file system check, thereby improving the resilience of the kernel against such corrupted checkpoint data.
Affected Version(s)
Linux 127e670abfa7fa150f6550d620ded930f5bdb4e7 < 550511a2470f6d204fa07b331f048bd2d3c51280
Linux 127e670abfa7fa150f6550d620ded930f5bdb4e7 < 8aad54746c251f2c2370118df766c0c82e2d2091
Linux 127e670abfa7fa150f6550d620ded930f5bdb4e7 < 2e12381d4495dc8b0ff042c6856022b2e359835c