Executive brief
A vulnerability in the Linux kernel's F2FS file system could allow a local attacker to cause a system crash or potentially access sensitive information. The issue occurs when the system processes extremely long file paths for storage devices, leading to memory errors. This could impact the reliability of systems using F2FS and potentially lead to unauthorized data access if exploited.
Technical details
An out-of-bounds read vulnerability (CWE-125) exists in the F2FS file system driver within the Linux kernel. The root cause is a missing null-terminator in the 'path' array of the 'f2fs_dev_info' structure when a device path length exactly equals MAX_PATH_LEN. When the kernel attempts to parse this path, it may read past the intended buffer into adjacent memory fields. A local attacker could exploit this by mounting a specially crafted F2FS image with long device paths, potentially leading to a kernel crash (DoS) or information disclosure. The vulnerability has been addressed by increasing the path buffer size by one byte to ensure space for a null terminator.
Affected products
- Linux Linux Kernel 4.10 to 6.15 (see patch links for specific stable branches)
Timeline
- 2025-07-11: patched: Initial fix authored by Chao Yu
- 2025-08-22: disclosed: CVE published
References
- https://git.kernel.org/stable/c/1b1efa5f0e878745e94a98022e8edc675a87d78e
- https://git.kernel.org/stable/c/1cf1ff15f262e8baf12201b270b6a79f9d119b2d
- https://git.kernel.org/stable/c/345fc8d1838f3f8be7c8ed08d86a13dedef67136
- https://git.kernel.org/stable/c/3466721f06edff834f99d9f49f23eabc6b2cb78e
- https://git.kernel.org/stable/c/5661998536af52848cc4d52a377e90368196edea
- https://git.kernel.org/stable/c/666b7cf6ac9aa074b8319a2b68cba7f2c30023f0
- https://git.kernel.org/stable/c/70849d33130a2cf1d6010069ed200669c8651fbd