Executive brief
A vulnerability in the Linux kernel's F2FS file system could lead to permanent data loss. When a new file is saved at the same time the system is performing a background maintenance task (a checkpoint), the system may incorrectly believe the data is safely stored on the disk when it is not. If the system loses power or crashes shortly after, the newly created file could be lost entirely.
Technical details
A race condition exists in the F2FS file system implementation within the Linux kernel due to the incorrect handling of nat_entry flags. Specifically, f2fs_flush_nat_entries() sets the IS_CHECKPOINTED and HAS_LAST_FSYNC flags before a checkpoint operation has actually completed. The function f2fs_need_inode_block_update() checks these flags without proper synchronization, leading it to incorrectly assume a checkpoint is finished and skip necessary node updates. This results in data loss for newly created files during a system crash or sudden power off (SPO). The fix involves acquiring the sbi->node_write lock in f2fs_need_inode_block_update() to ensure flag consistency.
Affected products
- Linux Linux Kernel 3.8 to 7.0.10
Timeline
- 2026-03-10: other: Vulnerability fixed in upstream code
- 2026-06-24: advisory: CVE-2026-53017 published