Junglewise Threat Intelligence

CVE-2026-43349: Linux kernel uninitialized memory access in f2fs node footer check

CVE-2026-43349 · Severity: medium · CVSS 5.5 · Published 2026-05-08

Technologies: Linux Kernel. Vendors: Linux.

Executive brief

A vulnerability was identified in the Linux kernel's Flash-Friendly File System (f2fs), which is commonly used on mobile devices and flash storage. The issue occurs when the system attempts to read data from a storage device and fails; it may then incorrectly try to process uninitialized memory as if it were valid file system data. This could lead to system instability or a kernel crash, potentially impacting the availability of the device.

Technical details

A vulnerability in the Linux kernel's f2fs file system involves an uninitialized value access within the f2fs_sanity_check_node_footer function. The root cause is located in f2fs_finish_read_bio(), where the kernel may attempt to perform sanity checks on a folio even if the underlying block I/O operation failed to populate it with data from the device. This results in the kernel accessing uninitialized memory. An attacker with the ability to trigger I/O errors or mount a specially crafted f2fs image could potentially cause a kernel panic (DoS). The fix introduces a check for the bio status (BLK_STS_OK) before proceeding with the sanity check. Patches have been merged into various stable branches of the Linux kernel.

Affected products

  • Linux Linux kernel f2fs file system

Timeline

  • 2026-03-09: other: Patch authored by Chao Yu
  • 2026-05-08: disclosed: CVE published

References

Related threats