Junglewise Threat Intelligence

CVE-2026-31715: Linux Kernel F2FS use-after-free in f2fs_write_end_io

CVE-2026-31715 · Severity: high · CVSS 7.8 · Published 2026-05-01

Technologies: Linux Kernel. Vendors: Linux.

Executive brief

A vulnerability in the Linux kernel's F2FS file system could allow a local user to cause a system crash (kernel panic). The issue occurs during specific file system operations, such as unmounting a drive, where a race condition leads to a memory error. This could disrupt operations or lead to a denial of service on affected systems.

Technical details

A use-after-free (UAF) vulnerability exists in the F2FS file system within the Linux kernel due to a race condition between the writeback callback and the unmount process. Specifically, in f2fs_write_end_io(), the code decrements the page count (sbi->nr_pages) before calling f2fs_in_warm_node_list(). If a concurrent unmount operation (f2fs_put_super) sees the page count reach zero, it proceeds to nullify sbi->node_inode. The subsequent call to f2fs_in_warm_node_list() then attempts to dereference this NULL pointer, resulting in a kernel panic. The fix involves reordering these operations so that the node list check occurs before the page count is decremented. This issue was identified via syzbot and xfstests.

Affected products

  • Linux Linux Kernel 4.19 to 6.18.25, 6.19 to 7.0.2, 7.1-rc1

Timeline

  • 2026-05-01: disclosed: Initial disclosure of CVE-2026-31715
  • 2026-05-01: advisory
  • 2026-03-24: patched: Mainline kernel patch committed

References