-

CVE-2026-89839

f2fs: use the mount idmap for the owner check in f2fs_xattr_advise_set()

In the Linux kernel, the following vulnerability has been resolved:

f2fs: use the mount idmap for the owner check in f2fs_xattr_advise_set()

f2fs_xattr_advise_set() calls inode_owner_or_capable() with &nop_mnt_idmap
before allowing the "system.advise" xattr to be set, instead of the idmap
that the VFS passes to the ->set() handler.

f2fs supports idmapped mounts, so on such a mount this checks the caller's
fsuid against the unmapped on-disk owner rather than the mapped owner: the
actual owner can be wrongly denied with -EPERM and an unrelated caller
wrongly allowed.  Pass the handler's idmap instead.
Daten sind bereitgestellt durch das CVE Programm von einer CVE Numbering Authority (CNA) (Unstrukturiert).
HerstellerLinux
≫
Produkt Linux
Default Statusunaffected
Version 01beba7957a26f9b7179127e8ad56bb5a0f56138
Version < 4c0c610b480cfbc57528aa1acbd6be12ed2a6fb1
Status affected
Version 01beba7957a26f9b7179127e8ad56bb5a0f56138
Version < c3e2692c7a58e0bdb84bd658d827e89dcecea3ad
Status affected
Version 01beba7957a26f9b7179127e8ad56bb5a0f56138
Version < 3b681229e9f8fb1dd29bc65983bf3c87779e4ca3
Status affected
Version 01beba7957a26f9b7179127e8ad56bb5a0f56138
Version < ab31e3b774f5d06b4489cef6c297b48c47c9dcbd
Status affected
Version 01beba7957a26f9b7179127e8ad56bb5a0f56138
Version < a54ffce4637acb0db8e695188a6c7f99f14c3576
Status affected
HerstellerLinux
≫
Produkt Linux
Default Statusaffected
Version 6.3
Status affected
Version 0
Version < 6.3
Status unaffected
Version <= 6.6.*
Version 6.6.157
Status unaffected
Version <= 6.12.*
Version 6.12.110
Status unaffected
Version <= 6.18.*
Version 6.18.51
Status unaffected
Version <= 7.2.*
Version 7.2.5
Status unaffected
Version <= *
Version 7.3-rc1
Status unaffected
VulnDex Vulnerability Enrichment
Diese Information steht angemeldeten Benutzern zur Verfügung. Login Login
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.2% 0.102
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
Es wurden noch keine Informationen zu CWE veröffentlicht.
https://git.kernel.org/stable/c/4c0c610b480cfbc57528aa1acbd6be12ed2a6fb1
https://git.kernel.org/stable/c/c3e2692c7a58e0bdb84bd658d827e89dcecea3ad
https://git.kernel.org/stable/c/3b681229e9f8fb1dd29bc65983bf3c87779e4ca3
https://git.kernel.org/stable/c/ab31e3b774f5d06b4489cef6c297b48c47c9dcbd
https://git.kernel.org/stable/c/a54ffce4637acb0db8e695188a6c7f99f14c3576