{"dataType":"CVE_RECORD","dataVersion":"5.2","cveMetadata":{"cveId":"CVE-2026-89829","assignerOrgId":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","state":"PUBLISHED","assignerShortName":"Linux","dateReserved":"2026-09-11T19:38:34.769Z","datePublished":"2026-09-16T10:31:01.761Z","dateUpdated":"2026-09-16T14:39:05.836Z"},"containers":{"cna":{"providerMetadata":{"orgId":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","shortName":"Linux","dateUpdated":"2026-09-16T14:39:05.836Z"},"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nf2fs: fix to pass folio->index to f2fs_sanity_check_node_footer()\n\nOtherwise in f2fs_sanity_check_node_footer(), it will check the\nsame nid incorrectly."}],"metrics":[{"cvssV3_1":{"version":"3.1","vectorString":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","baseScore":7.8,"baseSeverity":"HIGH"},"scenarios":[{"lang":"en","value":"AV:L - The defect is in f2fs __write_node_folio() on the node-mapping writeback path, reached only from local VFS operations (fsync, write, checkpoint, GC, or reclaim) on a mounted f2fs volume; no network protocol (ksmbd/nfsd/packet) processes this node-footer check.\nAC:L - A crafted f2fs image fully controls the on-disk node footer nid. Related syzbot reports show that async node readahead of a fuzzed image followed by writeback deterministically hits the mismatched-nid case, with no race or layout the attacker cannot arrange.\nPR:L - Mounting f2fs requires privilege (no FS_USERNS_MOUNT), but once the volume is mounted—Android userdata, automounted SD/USB, or a shared workstation—any unprivileged local user can dirty node pages via write/fsync/fallocate/truncate and enter __write_node_folio with no capability check.\nUI:N - After the crafted image is mounted, the attacker triggers node writeback themselves through ordinary file syscalls or in-kernel checkpoint/reclaim; no separate victim action such as opening a file or confirming a prompt is required.\nS:U - The impact is kernel memory and f2fs metadata corruption on the host that mounted the volume; it does not cross a VM, IOMMU, or guest-to-host security boundary.\nC:H - __write_node_folio uses the attacker-controlled footer nid as the NAT key without a range check, so current_nat_addr() indexes nat_bitmap at an attacker-chosen offset (nid/NAT_ENTRY_PER_BLOCK), an unbounded out-of-bounds kernel read. The same nid confusion later parses the planted node with the wrong layout, leaking adjacent folio contents as in CVE-2025-40025.\nI:H - set_node_addr() and f2fs_do_write_node_page() commit the node folio under the footer nid, overwriting an arbitrary NAT entry and remapping any node. Subsequent operations on that nid write through the wrong inode-vs-dnode layout, producing out-of-bounds metadata writes past the node folio.\nA:H - A mismatched nid that fails f2fs_get_node_info() takes redirty_out, looping writepages indefinitely (the hang this check was added to stop). A nid that proceeds hits f2fs_bug_on() in set_node_addr()/write_end_io, panicking with CONFIG_F2FS_CHECK_FS or WARNing and corrupting the filesystem otherwise."}]}],"affected":[{"product":"Linux","vendor":"Linux","defaultStatus":"unaffected","repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","programFiles":["fs/f2fs/node.c"],"versions":[{"version":"cd2fec912a0f04390d446ed692f73f2da842855f","lessThan":"a984446aa9d5b787afa3023fc7b44017b80fe3bc","status":"affected","versionType":"git"},{"version":"0a736109c9d29de0c26567e42cb99b27861aa8ba","lessThan":"0b196c07407f48a41cd9741cf53e10cb1e23d2e5","status":"affected","versionType":"git"},{"version":"0a736109c9d29de0c26567e42cb99b27861aa8ba","lessThan":"7e188e9f9437ab47c3237d609f1b26348d6fea1a","status":"affected","versionType":"git"},{"version":"971aa8e2a4043d92bf62061b79f74fd4ac59165a","status":"affected","versionType":"git"},{"version":"6.18.13","lessThan":"6.18.51","status":"affected","versionType":"semver"},{"version":"6.19.3","lessThan":"6.20","status":"affected","versionType":"semver"}]},{"product":"Linux","vendor":"Linux","defaultStatus":"affected","repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","programFiles":["fs/f2fs/node.c"],"versions":[{"version":"7.0","status":"affected"},{"version":"0","lessThan":"7.0","status":"unaffected","versionType":"semver"},{"version":"6.18.51","lessThanOrEqual":"6.18.*","status":"unaffected","versionType":"semver"},{"version":"7.2.5","lessThanOrEqual":"7.2.*","status":"unaffected","versionType":"semver"},{"version":"7.3-rc1","lessThanOrEqual":"*","status":"unaffected","versionType":"original_commit_for_fix"}]}],"cpeApplicability":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"6.18.13","versionEndExcluding":"6.18.51"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"7.0","versionEndExcluding":"7.2.5"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"7.0","versionEndExcluding":"7.3-rc1"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"6.19.3"}]}]}],"references":[{"url":"https://git.kernel.org/stable/c/a984446aa9d5b787afa3023fc7b44017b80fe3bc"},{"url":"https://git.kernel.org/stable/c/0b196c07407f48a41cd9741cf53e10cb1e23d2e5"},{"url":"https://git.kernel.org/stable/c/7e188e9f9437ab47c3237d609f1b26348d6fea1a"}],"title":"f2fs: fix to pass folio->index to f2fs_sanity_check_node_footer()","x_generator":{"engine":"bippy-1.2.0"}}}}