GHSA-6fmr-6rhp-m3p8HighCVSS 7.1
In the Linux kernel, the following vulnerability has been resolved: f2fs: validate MOVE_RANGE...
🔗 CVE IDs covered (1)
📋 Description
In the Linux kernel, the following vulnerability has been resolved:
f2fs: validate MOVE_RANGE destination size
F2FS_IOC_MOVE_RANGE checks the source range, but not the destination end before updating i_size. A source hole can expose this: __clone_blkaddrs() skips NULL_ADDR entries and returns success, so the caller can still extend the destination inode with unchecked pos_out + len.
Reject destination overflow and use inode_newsize_ok() before extending the destination inode.
🔗 References (6)
- https://nvd.nist.gov/vuln/detail/CVE-2026-89840
- https://git.kernel.org/stable/c/dcae1eeda53149f219dd6af93b3083b7271c1c63
- https://git.kernel.org/stable/c/e533889fc26aea0cd83c90327063f272061dd820
- https://git.kernel.org/stable/c/db13064669526494cd78ba3a4394063b740e940c
- https://git.kernel.org/stable/c/bca61ee5192ea47003722486ae9588a2a4bb47b6
- https://github.com/advisories/GHSA-6fmr-6rhp-m3p8