In the Linux kernel, the following vulnerability has been resolved:
f2fs: fix to avoid NULL pointer dereference in f2fs_check_quota_consistency()
syzbot reported a f2fs bug as below:
Oops: gen[ 107.736417][ T5848] Oops: general protection fault, probably for non-canonical address 0xdffffc0000000000: 0000 [#1] SMP KASAN PTI KASAN: null-ptr-deref in range [0x0000000000000000-0x0000000000000007] CPU: 1 UID: 0 PID: 5848 Comm: syz-executor263 Tainted: G W 6.17.0-rc1-syzkaller-00014-g0e39a731820a #0 PREEMPT_{RT,(full)} RIP: 0010:strcmp+0x3c/0xc0 lib/string.c:284 Call Trace: <TASK> f2fs_check_quota_consistency fs/f2fs/super.c:1188 [inline] f2fs_check_opt_consistency+0x1378/0x2c10 fs/f2fs/super.c:1436 __f2fs_remount fs/f2fs/super.c:2653 [inline] f2fs_reconfigure+0x482/0x1770 fs/f2fs/super.c:5297 reconfigure_super+0x224/0x890 fs/super.c:1077 do_remount fs/namespace.c:3314 [inline] path_mount+0xd18/0xfe0 fs/namespace.c:4112 do_mount fs/namespace.c:4133 [inline] __do_sys_mount fs/namespace.c:4344 [inline] __se_sys_mount+0x317/0x410 fs/namespace.c:4321 do_syscall_x64 arch/x86/entry/syscall_64.c:63 [inline] do_syscall_64+0xfa/0x3b0 arch/x86/entry/syscall_64.c:94 entry_SYSCALL_64_after_hwframe+0x77/0x7f
The direct reason is f2fs_check_quota_consistency() may suffer null-ptr-deref issue in strcmp().
The bug can be reproduced w/ below scripts: mkfs.f2fs -f /dev/vdb mount -t f2fs -o usrquota /dev/vdb /mnt/f2fs quotacheck -uc /mnt/f2fs/ umount /mnt/f2fs mount -t f2fs -o usrjquota=aquota.user,jqfmt=vfsold /dev/vdb /mnt/f2fs mount -t f2fs -o remount,usrjquota=,jqfmt=vfsold /dev/vdb /mnt/f2fs umount /mnt/f2fs
So, before old_qname and new_qname comparison, we need to check whether they are all valid pointers, fix it.
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Ubuntu | — | Upgrade linux-image-raspiUpgrade linux-image-aws-64kUpgrade linux-image-oracle-6.17Upgrade linux-image-oracle-64kUpgrade linux-image-gcp-6.17Upgrade linux-image-azureUpgrade linux-image-gcp-64kUpgrade linux-image-6.17.0-1007-gcpUpgrade linux-image-oem-6.17Upgrade linux-image-realtime-6.17Upgrade linux-image-virtualUpgrade linux-image-6.17.0-1008-raspiUpgrade linux-image-gcpUpgrade linux-image-raspi-6.17Upgrade linux-image-6.17.0-1006-realtimeUpgrade linux-image-6.17.0-1007-awsUpgrade linux-image-realtimeUpgrade linux-image-6.17.0-1007-oracleUpgrade linux-image-awsUpgrade linux-image-virtual-6.17Upgrade linux-image-generic-6.17Upgrade linux-image-generic-64k-6.17Upgrade linux-image-genericUpgrade linux-image-gcp-64k-6.17Upgrade linux-image-azure-6.17Upgrade linux-image-6.17.0-1007-gcp-64kUpgrade linux-image-oracleUpgrade linux-image-6.17.0-1011-oemUpgrade linux-image-6.17.0-1007-aws-64kUpgrade linux-image-oracle-64k-6.17Upgrade linux-image-6.17.0-1008-azureUpgrade linux-image-aws-6.17Upgrade linux-image-6.17.0-14-generic-64kUpgrade linux-image-generic-64kUpgrade linux-image-aws-64k-6.17Upgrade linux-image-6.17.0-14-genericUpgrade linux-image-6.17.0-1007-oracle-64k | Feb 13, 2026 | Feb 12, 2026 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub