{"dataType":"CVE_RECORD","dataVersion":"5.2","cveMetadata":{"cveId":"CVE-2026-46175","assignerOrgId":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","state":"PUBLISHED","assignerShortName":"Linux","dateReserved":"2026-05-13T15:03:33.103Z","datePublished":"2026-05-28T09:36:29.522Z","dateUpdated":"2026-08-05T12:30:13.236Z"},"containers":{"cna":{"providerMetadata":{"orgId":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","shortName":"Linux","dateUpdated":"2026-08-05T12:30:13.236Z"},"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nf2fs: fix fsck inconsistency caused by FGGC of node block\n\nDuring FGGC node block migration, fsck may incorrectly treat the\nmigrated node block as fsync-written data.\n\nThe reproduction scenario:\nroot@vm:/mnt/f2fs# seq 1 2048 | xargs -n 1 ./test_sync // write inline inode and sync\nroot@vm:/mnt/f2fs# rm -f 1\nroot@vm:/mnt/f2fs# sync\nroot@vm:/mnt/f2fs# f2fs_io gc_range // move data block in sync mode and not write CP\n  SPO, \"fsck --dry-run\" find inode has already checkpointed but still\n  with DENT_BIT_SHIFT set\n\nThe root cause is that GC does not clear the dentry mark and fsync mark\nduring node block migration, leading fsck to misinterpret them as\nuser-issued fsync writes.\n\nIn BGGC mode, node block migration is handled by f2fs_sync_node_pages(),\nwhich guarantees the dentry and fsync marks are cleared before writing.\n\nThis patch move the set/clear of the fsync|dentry marks into\n__write_node_folio to make the logic clearer, and ensures the\nfsync|dentry mark is cleared in FGGC."}],"metrics":[{"cvssV3_1":{"version":"3.1","vectorString":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H","baseScore":7.1,"baseSeverity":"HIGH"},"scenarios":[{"lang":"en","value":"AV:L - f2fs is a local block-device filesystem (default on Android/embedded); the vulnerable FGGC path is reached only by a local actor writing to a mounted f2fs volume, not over any network.\nAC:L - The attacker fully sets up the trigger (write+fsync an inline inode, delete it, exhaust free space to force FGGC of its node block); the corrupt on-disk state then persists until the next checkpoint, and routine power cycles/reboots on the target devices reliably invoke the faulty recovery.\nPR:L - While the GC ioctls require CAP_SYS_ADMIN, automatic foreground GC (f2fs_balance_fs → f2fs_gc promoting to FG_GC on low free space) runs the exact vulnerable path for any unprivileged user with write access to the filesystem.\nUI:N - Roll-forward recovery runs automatically during the next mount after a crash; no victim action is needed beyond the normal, automatic crash-and-remount cycle.\nS:U - The corruption is confined to the f2fs on-disk structures and the kernel managing them; it does not cross into a different security authority.\nC:N - The bug corrupts filesystem-consistency metadata but provides no read primitive over kernel memory or otherwise-inaccessible data, so there is no information disclosure.\nI:H - The migrated node block is misinterpreted as fsynced data, causing incorrect roll-forward recovery that resurrects deleted/stale inode metadata and leaves the on-disk filesystem inconsistent (fsck-detected) — a serious integrity compromise of stored data.\nA:H - A bad recovery can return an error, aborting the mount and rendering the filesystem/data unavailable until offline fsck (e.g. /data mount failure), and with CONFIG_F2FS_CHECK_FS the recovery error path hits BUG_ON(), crashing the kernel."}]}],"affected":[{"product":"Linux","vendor":"Linux","defaultStatus":"unaffected","repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","programFiles":["fs/f2fs/node.c"],"versions":[{"version":"da011cc0da8cf4a60ddf4d2ae8b42902a3d71e5f","lessThan":"8be551f538dc5b64183e27bd45a7a0795263f760","status":"affected","versionType":"git"},{"version":"da011cc0da8cf4a60ddf4d2ae8b42902a3d71e5f","lessThan":"e7c6d30169b03307d27c4479563df79c08f3a746","status":"affected","versionType":"git"},{"version":"da011cc0da8cf4a60ddf4d2ae8b42902a3d71e5f","lessThan":"c3e238bd1f56993f205ef83889d406dfeaf717a8","status":"affected","versionType":"git"}]},{"product":"Linux","vendor":"Linux","defaultStatus":"affected","repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","programFiles":["fs/f2fs/node.c"],"versions":[{"version":"4.7","status":"affected"},{"version":"0","lessThan":"4.7","status":"unaffected","versionType":"semver"},{"version":"6.18.30","lessThanOrEqual":"6.18.*","status":"unaffected","versionType":"semver"},{"version":"7.0.7","lessThanOrEqual":"7.0.*","status":"unaffected","versionType":"semver"},{"version":"7.1","lessThanOrEqual":"*","status":"unaffected","versionType":"original_commit_for_fix"}]}],"cpeApplicability":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"4.7","versionEndExcluding":"6.18.30"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"4.7","versionEndExcluding":"7.0.7"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"4.7","versionEndExcluding":"7.1"}]}]}],"references":[{"url":"https://git.kernel.org/stable/c/8be551f538dc5b64183e27bd45a7a0795263f760"},{"url":"https://git.kernel.org/stable/c/e7c6d30169b03307d27c4479563df79c08f3a746"},{"url":"https://git.kernel.org/stable/c/c3e238bd1f56993f205ef83889d406dfeaf717a8"}],"title":"f2fs: fix fsck inconsistency caused by FGGC of node block","x_generator":{"engine":"bippy-1.2.0"}}}}