Executive brief
A vulnerability exists in the Linux kernel's F2FS file system, which is commonly used on flash-based storage like smartphones and SSDs. A race condition during the unmounting of a drive can cause the system to attempt to use memory that has already been freed. This could lead to a system crash or potentially allow a local attacker to gain unauthorized access or execute malicious code.
Technical details
A use-after-free (UAF) vulnerability exists in fs/f2fs/compress.c within the f2fs_compress_write_end_io() function. The root cause is a race condition where dec_page_count() decrements the F2FS_WB_CP_DATA counter too early, potentially unblocking a concurrent f2fs_put_super() call on another CPU. If the unmount path proceeds to destroy the sbi structure and its associated slab caches (sbi->page_array_slab) while the bio completion callback is still executing, a subsequent call to page_array_free() will dereference the destroyed slab cache. This is a local attack vector requiring no user interaction. The fix involves reordering dec_page_count() to ensure it is the final operation accessing the sbi structure.
Affected products
- Linux Linux Kernel 5.6 to 6.6.136, 6.7 to 6.12.84, 6.13 to 6.18.25, 6.19 to 7.0.2
Timeline
- 2026-03-23: patched: Initial patch authored by George Saad
- 2026-05-01: disclosed: CVE published
References
- https://git.kernel.org/stable/c/2c97dcb6147c8f7f25c629b93be1e69617de5d4a
- https://git.kernel.org/stable/c/39d4ee19c1e7d753dd655aebee632271b171f43a
- https://git.kernel.org/stable/c/57bc678f36ac03281e877c6b84877b43f964143f
- https://git.kernel.org/stable/c/c76cf339b87975ae5b2c06d2d774d5667d25a12a
- https://git.kernel.org/stable/c/ef57cd3329b40c739b9a2e1a8a21ecc4171c6280
- https://git.kernel.org/stable/c/f5154cf3ce1c8193f0c1891d3769f62740cfe6fe