CVE-2026-89840

Summary

In the Linux kernel, the following vulnerability has been resolved:

f2fs: validate MOVE_RANGE destination size

F2FS_IOC_MOVE_RANGE checks the source range, but not the destination end before updating i_size. A source hole can expose this: __clone_blkaddrs() skips NULL_ADDR entries and returns success, so the caller can still extend the destination inode with unchecked pos_out + len.

Reject destination overflow and use inode_newsize_ok() before extending the destination inode.

Affected Software

VendorProductVersion RangeStatus
LinuxLinux4dd6f977fc778e5a0da604e5f8cb2f36d163d27b < dcae1eeda53149f219dd6af93b3083b7271c1c63affected
LinuxLinux4dd6f977fc778e5a0da604e5f8cb2f36d163d27b < e533889fc26aea0cd83c90327063f272061dd820affected
LinuxLinux4.8affected
LinuxLinux0 < 4.8unaffected
LinuxLinux7.2.5 <= 7.2.*unaffected
LinuxLinux7.3-rc1 <= *unaffected

Weaknesses

References