CVE-2026-89840
7.1
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H
Summary
In the Linux kernel, the following vulnerability has been resolved:
f2fs: validate MOVE_RANGE destination size
F2FS_IOC_MOVE_RANGE checks the source range, but not the destination end before updating i_size. A source hole can expose this: __clone_blkaddrs() skips NULL_ADDR entries and returns success, so the caller can still extend the destination inode with unchecked pos_out + len.
Reject destination overflow and use inode_newsize_ok() before extending the destination inode.
Affected Software
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| Linux | Linux | 4dd6f977fc778e5a0da604e5f8cb2f36d163d27b < dcae1eeda53149f219dd6af93b3083b7271c1c63 | affected |
| Linux | Linux | 4dd6f977fc778e5a0da604e5f8cb2f36d163d27b < e533889fc26aea0cd83c90327063f272061dd820 | affected |
| Linux | Linux | 4.8 | affected |
| Linux | Linux | 0 < 4.8 | unaffected |
| Linux | Linux | 7.2.5 <= 7.2.* | unaffected |
| Linux | Linux | 7.3-rc1 <= * | unaffected |
Weaknesses
References
- https://git.kernel.org/stable/c/dcae1eeda53149f219dd6af93b3083b7271c1c63
- https://git.kernel.org/stable/c/e533889fc26aea0cd83c90327063f272061dd820
Feedback
Was this page helpful?
Glad to hear it! Please tell us how we can improve.
Sorry to hear that. Please tell us how we can improve.