Junglewise Threat Intelligence

CVE-2026-31702: Linux Kernel F2FS use-after-free in f2fs_compress_write_end_io

CVE-2026-31702 · Severity: high · CVSS 7.8 · Published 2026-05-01

Technologies: Linux Kernel. Vendors: Linux.

Executive brief

A vulnerability exists in the Linux kernel's F2FS file system, which is commonly used on flash-based storage like smartphones and SSDs. A race condition during the unmounting of a drive can cause the system to attempt to use memory that has already been freed. This could lead to a system crash or potentially allow a local attacker to gain unauthorized access or execute malicious code.

Technical details

A use-after-free (UAF) vulnerability exists in fs/f2fs/compress.c within the f2fs_compress_write_end_io() function. The root cause is a race condition where dec_page_count() decrements the F2FS_WB_CP_DATA counter too early, potentially unblocking a concurrent f2fs_put_super() call on another CPU. If the unmount path proceeds to destroy the sbi structure and its associated slab caches (sbi->page_array_slab) while the bio completion callback is still executing, a subsequent call to page_array_free() will dereference the destroyed slab cache. This is a local attack vector requiring no user interaction. The fix involves reordering dec_page_count() to ensure it is the final operation accessing the sbi structure.

Affected products

  • Linux Linux Kernel 5.6 to 6.6.136, 6.7 to 6.12.84, 6.13 to 6.18.25, 6.19 to 7.0.2

Timeline

  • 2026-03-23: patched: Initial patch authored by George Saad
  • 2026-05-01: disclosed: CVE published

References

Related threats