Executive brief
A vulnerability was identified in the Linux kernel's F2FS file system, which is commonly used on Android devices and flash storage. This flaw could allow a local user to cause a system crash or potentially gain unauthorized access to data by triggering a memory error during file synchronization. The issue has been resolved in recent kernel updates.
Technical details
A use-after-free (UAF) vulnerability exists in the F2FS file system within the f2fs_sync_inode_meta() function. The root cause is a race condition or improper reference counting during inode eviction and writeback, where the kernel attempts to access or delete a list entry (__list_del_entry_valid) for an inode that has already been freed. This was discovered via syzbot and KASAN. An attacker with local access could exploit this to cause a kernel panic (DoS) or execute arbitrary code in the context of the kernel. Patches have been released across multiple stable kernel branches (e.g., 6.1.y, 6.6.y, etc.).
Affected products
- Linux Linux Kernel 6.1.129-syzkaller-00017-g642656a36791 and earlier versions
Timeline
- 2025-07-08: patched: Initial patch authored by Chao Yu
- 2025-08-19: disclosed: CVE published
- 2025-08-28: advisory: Stable kernel tree commits applied
References
- https://git.kernel.org/stable/c/1edf68272b8cba2b2817ef1488ecb9f0f84cb6a0
- https://git.kernel.org/stable/c/37e78cad7e9e025e63bb35bc200f44637b009bb1
- https://git.kernel.org/stable/c/3d37cadaac1a8e108e576297aab9125b24ea2dfe
- https://git.kernel.org/stable/c/4dcd830c420f2190ae32f03626039fde7b57b2ad
- https://git.kernel.org/stable/c/6cac47af39b2b8edbb41d47c3bd9c332f83e9932
- https://git.kernel.org/stable/c/7c30d79930132466f5be7d0b57add14d1a016bda
- https://git.kernel.org/stable/c/917ae5e280bc263f56c83fba0d0f0be2c4828083