Executive brief
A vulnerability was identified in the Linux kernel's Flash-Friendly File System (F2FS), which is commonly used on mobile devices and flash storage. The flaw could allow a local user to cause a system crash (kernel panic) or potentially execute unauthorized actions by triggering a memory error during file system operations. This impact could lead to a complete loss of system availability and potential data corruption.
Technical details
A use-after-free (UAF) vulnerability exists in the Linux kernel's F2FS file system, specifically within the inode eviction and synchronization path. The issue is triggered when `f2fs_evict_inode` or related functions like `f2fs_inode_synced` attempt to manipulate a list entry for an inode that has already been freed, as detected by KASAN in `__list_del_entry_valid`. The vulnerability is reachable via local system calls that trigger file system writebacks or checkpoints, such as during unmounting or system exit. An attacker with local access could exploit this to cause a denial-of-service (kernel panic) or potentially achieve local privilege escalation. Patches have been released across multiple stable kernel branches.
Affected products
- Linux Linux kernel 6.1.129-syzkaller and other versions prior to the fix
Timeline
- 2025-07-08: patched: Original patch authored by Chao Yu
- 2025-08-19: disclosed: CVE published
References
- https://git.kernel.org/stable/c/15df59809c54fbd687cdf27efbd2103a937459be
- https://git.kernel.org/stable/c/42f9ea16aea8b49febaa87950a006a1792209f38
- https://git.kernel.org/stable/c/4732ca17c17f5062426cfa982f43593e6b81963b
- https://git.kernel.org/stable/c/5cd99d5aa3d39086bdb53eb5c52df16e98b101a0
- https://git.kernel.org/stable/c/880ef748e78a1eb7df2d8e11a9ef21e98bcaabe5
- https://git.kernel.org/stable/c/9535e440fe5bc6c5ac7cfb407e53bf788b8bf8d4
- https://git.kernel.org/stable/c/97df495d754116c8c28ac6a4112f831727bde887