Executive brief
A vulnerability exists in the Linux kernel's F2FS file system, which is commonly used on flash-based storage like smartphones. A technical flaw in how the system handles 'atomic writes' (a method for ensuring data is saved correctly) can lead to a system crash. This occurs when the system tries to clean up storage space while a file is being deleted, potentially allowing a local user to cause a denial-of-service.
Technical details
A use-after-free (UAF) vulnerability exists in the F2FS file system implementation within the Linux kernel. The issue occurs in the interaction between garbage collection (via ioctl F2FS_IOC_GARBAGE_COLLECT_RANGE) and inode eviction. Specifically, the ra_data_block and move_data_block functions access the mapping field of an atomic_inode without holding a proper reference. If f2fs_evict_inode is called concurrently, it can nullify and free the atomic_inode, leading to a UAF when the garbage collector subsequently attempts to grab a cache folio. This results in a kernel BUG_ON or null pointer dereference. The fix involves using igrab() to ensure the inode remains valid during the operation.
Affected products
- Linux Linux Kernel 5.19 to 6.12.96, 6.18.39, 7.1.3
Timeline
- 2026-07-03: patched: Initial fix authored by Chao Yu
- 2026-07-19: disclosed: CVE published