Executive brief
A race condition in the Linux kernel's F2FS file system could lead to data inconsistency on the disk. This occurs when internal file system flags are updated without proper synchronization during a system checkpoint. While primarily affecting system maintenance tools like fsck, it could potentially lead to minor file system corruption or incorrect reporting of file states after a sudden power loss or system crash.
Technical details
A race condition exists in the F2FS file system where f2fs_need_dentry_mark() reads nat_entry flags without mutual exclusion from the checkpoint path. This lack of synchronization can result in an incorrect inode block marking state (DENT_BIT_SHIFT) because the semantics of IS_CHECKPOINTED and HAS_FSYNCED_INODE are only guaranteed after a checkpoint write is fully completed. An attacker or system event could trigger a scenario where an inode is checkpointed but retains incorrect flags, leading to inconsistencies detectable by fsck. The fix involves moving set_dentry_mark() into __write_node_folio() and protecting it with the sbi->node_write lock to ensure atomicity.
Affected products
- Linux Linux Kernel 3.18 to 6.18.30, 7.0.7
Timeline
- 2026-07-19: disclosed: CVE published
- 2026-03-10: patched: Initial fix authored by Yongpeng Yang