Executive brief
A vulnerability in the Linux kernel's F2FS file system can cause the entire system to crash (kernel panic) when the storage partition is nearly full. This occurs due to a technical error in how the system manages memory during background maintenance tasks like garbage collection. An exploit or even normal high-usage conditions could lead to service outages and data unavailability.
Technical details
A race condition exists in the F2FS file system's move_data_block() function involving the garbage collection (GC) path and folio management. When the GC path evicts a tail-end folio from the page cache via folio_end_dropbehind(), it can create a scenario where subpages are no longer protected by page-cache references during a split operation. This allows split_folio_to_order() and folio_isolate_lru() to race, resulting in a page being freed back to the allocator while its LRU (Least Recently Used) links remain active. Subsequent LRU operations detect this stale link, triggering a kernel BUG and system panic. The issue is most prevalent when the F2FS partition is nearly full. The fix involves reverting the commit that introduced the aggressive folio eviction logic.
Affected products
- Linux Linux Kernel f2fs file system
Timeline
- 2026-06-08: other: Patch authored
- 2026-07-18: patched: Patch committed to stable tree
- 2026-07-19: disclosed: CVE published