CVE-2026-89838

Summary

In the Linux kernel, the following vulnerability has been resolved:

f2fs: limit recovery filename logging to stored length

F2FS stores recovery filenames as a length plus a fixed-size i_name buffer. The buffer is not NUL-terminated, but recover_inode() and recover_dentry() print it with %s.

For a 255-byte filename, recovery logging can read past i_name into the following raw inode fields.

Print the name with a precision bounded by i_namelen and F2FS_NAME_LEN.

Affected Software

VendorProductVersion RangeStatus
LinuxLinuxf356fe0cba0e3523e538987916bd2acedd4e6f41 < 317d32e1a8deaf1c01c388badc667334c39e62caaffected
LinuxLinuxf356fe0cba0e3523e538987916bd2acedd4e6f41 < 01027b2fcb74dade59fb833b51023f6593b6a9a2affected
LinuxLinux3.11affected
LinuxLinux0 < 3.11unaffected
LinuxLinux7.2.5 <= 7.2.*unaffected
LinuxLinux7.3-rc1 <= *unaffected

Weaknesses

References