7.8

CVE-2026-89841

f2fs: only redirty pinned folios in redirty_blocks

In the Linux kernel, the following vulnerability has been resolved:

f2fs: only redirty pinned folios in redirty_blocks

redirty_blocks() pins folios with read_cache_folio() and then walks the
same range again with filemap_lock_folio() to redirty them and drop the
references it took.

Commit 5951fee46bef ("f2fs: Use a folio in redirty_blocks()") changed
the second pass to a do/while loop. If read_cache_folio() fails before
anything is pinned, page_idx does not advance but the cleanup loop still
runs once.

If readahead has already populated the failed folio in page cache, that
extra iteration finds it and folio_put_refs(folio, 2) drops one
reference too many. Later drop_caches or reclaim can then report
"BUG: Bad page state".

Only redirty the range that was pinned successfully.
Daten sind bereitgestellt durch das CVE Programm von einer CVE Numbering Authority (CNA) (Unstrukturiert).
HerstellerLinux
≫
Produkt Linux
Default Statusunaffected
Version 5951fee46befbf6176c86482432f4f76e522f16c
Version < 445e4a1e6025ecd5312e9a95c1b234192c976ca1
Status affected
Version 5951fee46befbf6176c86482432f4f76e522f16c
Version < 89c65ec3c18903de763cf567c96ab3ef60e5f3b0
Status affected
Version 5951fee46befbf6176c86482432f4f76e522f16c
Version < 85171332742e741ccd6f401c69b6e0d698119e72
Status affected
HerstellerLinux
≫
Produkt Linux
Default Statusaffected
Version 6.16
Status affected
Version 0
Version < 6.16
Status unaffected
Version <= 6.18.*
Version 6.18.51
Status unaffected
Version <= 7.2.*
Version 7.2.5
Status unaffected
Version <= *
Version 7.3-rc1
Status unaffected
VulnDex Vulnerability Enrichment
Diese Information steht angemeldeten Benutzern zur Verfügung. Login Login
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.16% 0.058
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
416baaa9-dc9f-4396-8d5f-8c081fb06d67 7.8 1.8 5.9
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Es wurden noch keine Informationen zu CWE veröffentlicht.
https://git.kernel.org/stable/c/445e4a1e6025ecd5312e9a95c1b234192c976ca1
https://git.kernel.org/stable/c/89c65ec3c18903de763cf567c96ab3ef60e5f3b0
https://git.kernel.org/stable/c/85171332742e741ccd6f401c69b6e0d698119e72