In the Linux kernel, the following vulnerability has been resolved:
f2fs: fix to do sanity check on summary info
As Wenqing Liu reported in bugzilla:
https://bugzilla.kernel.org/show_bug.cgi?id=216456
BUG: KASAN: use-after-free in recover_data+0x63ae/0x6ae0 [f2fs] Read of size 4 at addr ffff8881464dcd80 by task mount/1013
CPU: 3 PID: 1013 Comm: mount Tainted: G W 6.0.0-rc4 #1 Hardware name: QEMU Standard PC (Q35 + ICH9, 2009), BIOS 1.15.0-1 04/01/2014 Call Trace: dump_stack_lvl+0x45/0x5e print_report.cold+0xf3/0x68d kasan_report+0xa8/0x130 recover_data+0x63ae/0x6ae0 [f2fs] f2fs_recover_fsync_data+0x120d/0x1fc0 [f2fs] f2fs_fill_super+0x4665/0x61e0 [f2fs] mount_bdev+0x2cf/0x3b0 legacy_get_tree+0xed/0x1d0 vfs_get_tree+0x81/0x2b0 path_mount+0x47e/0x19d0 do_mount+0xce/0xf0 __x64_sys_mount+0x12c/0x1a0 do_syscall_64+0x38/0x90 entry_SYSCALL_64_after_hwframe+0x63/0xcd
The root cause is: in fuzzed image, SSA table is corrupted: ofs_in_node is larger than ADDRS_PER_PAGE(), result in out-of-range access on 4k-size page.
- recover_data - do_recover_data - check_index_in_prev_nodes - f2fs_data_blkaddr
This patch adds sanity check on summary info in recovery and GC flow in where the flows rely on them.
After patch: [ 29.310883] F2FS-fs (loop0): Inconsistent ofs_in_node:65286 in summary, ino:0, nid:6, max:1018
CVSS Details
- CVSS 3.1 Base Score: 7.8
- CVSS 3.1 Vector: (CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Debian | — | Upgrade linux | Dec 29, 2025 | Dec 29, 2025 |
| Ubuntu | — | Upgrade linux-oracle-5.4Upgrade linux-aws-5.4Upgrade linux-bluefieldUpgrade linux-aws-5.15Upgrade linux-iotUpgrade linux-lowlatency-hwe-5.15Upgrade linux-azureUpgrade linux-intel-iotg-5.15Upgrade linux-hwe-5.15Upgrade linux-awsUpgrade linux-riscv-5.15Upgrade linux-azure-fdeUpgrade linux-gkeUpgrade linux-realtimeUpgrade linux-raspiUpgrade linux-intel-iotgUpgrade linux-gcp-5.15Upgrade linux-raspi-5.4Upgrade linux-kvmUpgrade linux-fipsUpgrade linux-oracle-5.15Upgrade linux-azure-fipsUpgrade linux-gkeopUpgrade linux-lowlatencyUpgrade linux-oracleUpgrade linuxUpgrade linux-azure-5.15Upgrade linux-gcpUpgrade linux-ibm-5.4Upgrade linux-xilinx-zynqmpUpgrade linux-gcp-fipsUpgrade linux-azure-5.4Upgrade linux-ibmUpgrade linux-gcp-5.4Upgrade linux-aws-fipsUpgrade linux-hwe-5.4Upgrade linux-nvidia | Jan 6, 2026 | Dec 24, 2025 |
| Vmware Photon_os | — | Use 'tdnf update' to upgrade all packages to the latest version. | May 27, 2026 | Dec 24, 2025 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub