Executive brief
The Linux kernel's file system verification (fs-verity) feature includes a check to prevent truncating protected files. A logic error in this protection mechanism allows truncation on fs-verity files in certain configurations, potentially enabling unauthorized modification of integrity-protected file content and bypassing file authenticity guarantees.
Technical details
This vulnerability exists in the setattr_prepare() function in fs/attr.c, which is responsible for validating file attribute changes. The check to prevent truncation on fs-verity protected files was unnecessarily gated by IS_ENABLED(CONFIG_FS_VERITY), a compile-time configuration check. This meant that even if a filesystem contained fs-verity protected files, if CONFIG_FS_VERITY was disabled at compile time, the truncation protection would not be enforced. An attacker with local file system access could truncate fs-verity protected files, defeating the integrity verification mechanism. The fix removes the CONFIG_FS_VERITY compile-time check, relying instead on the IS_VERITY() runtime check which properly detects whether individual files are actually protected. Local file system access is required to exploit this.
Affected products
- Linux Linux kernel multiple versions (see upstream fix d2f96bcb89d36d488a10e3bcf819b98536968286)
Timeline
- 2026-08-22: disclosed
- 2026-07-28: patched