{"dataType":"CVE_RECORD","dataVersion":"5.2","cveMetadata":{"cveId":"CVE-2026-89840","assignerOrgId":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","state":"PUBLISHED","assignerShortName":"Linux","dateReserved":"2026-09-11T19:38:34.769Z","datePublished":"2026-09-16T10:31:14.646Z","dateUpdated":"2026-10-03T10:56:48.043Z"},"containers":{"cna":{"providerMetadata":{"orgId":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","shortName":"Linux","dateUpdated":"2026-10-03T10:56:48.043Z"},"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nf2fs: validate MOVE_RANGE destination size\n\nF2FS_IOC_MOVE_RANGE checks the source range, but not the destination end\nbefore updating i_size. A source hole can expose this: __clone_blkaddrs()\nskips NULL_ADDR entries and returns success, so the caller can still extend\nthe destination inode with unchecked pos_out + len.\n\nReject destination overflow and use inode_newsize_ok() before extending\nthe destination inode."}],"metrics":[{"cvssV3_1":{"version":"3.1","vectorString":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H","baseScore":7.1,"baseSeverity":"HIGH"},"scenarios":[{"lang":"en","value":"AV:L - F2FS_IOC_MOVE_RANGE is a local ioctl (f2fs_ioctl → f2fs_ioc_move_range → f2fs_move_file_range) on f2fs file descriptors. f2fs has no remap_file_range, so nfsd/ksmbd copy_file_range cannot reach this path.\nAC:L - The attacker fully controls pos_out and len and can ftruncate a sparse source so __clone_blkaddrs skips NULL_ADDR holes and returns success, making the unchecked destination i_size update deterministic with no race or uncontrollable layout.\nPR:L - f2fs_ioc_move_range has no capable() check; it only needs FMODE_READ|FMODE_WRITE on the source and FMODE_WRITE on the destination. Any unprivileged user with files on mounted f2fs (Android /data, embedded userdata) can trigger it.\nUI:N - The attacker opens their own files on an already-mounted f2fs volume and issues F2FS_IOC_MOVE_RANGE; no separate victim action such as mounting a filesystem or opening a crafted file is required.\nS:U - Impact is corruption of f2fs inode size metadata and subsequent filesystem/kernel state on the local host, a standard kernel compromise within the same security authority with no VM escape or IOMMU bypass.\nC:N - The bug writes an oversized or overflowed i_size; reads of the resulting sparse file return zeros or EOF (negative i_size makes pos >= i_size), and lookups beyond max_file_blocks fail with -E2BIG, so there is no kernel-memory or cross-file disclosure primitive.\nI:H - Missing overflow and inode_newsize_ok() checks let the attacker set destination i_size past s_maxbytes or wrap size_t into a negative loff_t, persisting corrupt on-disk inode size and poisoning later paths (fallocate COLLAPSE nrpages, __exchange_data_block ALLOC_NODE) that trust i_size for block-tree updates.\nA:H - A poisoned i_size enables unbounded node-tree walks and block-exchange loops (SEEK_DATA/HOLE, fallocate COLLAPSE via DIV_ROUND_UP(i_size)), can hang the kernel or exhaust node space, and leaves durable filesystem corruption on shared f2fs userdata."}]}],"affected":[{"product":"Linux","vendor":"Linux","defaultStatus":"unaffected","repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","programFiles":["fs/f2fs/file.c"],"versions":[{"version":"4dd6f977fc778e5a0da604e5f8cb2f36d163d27b","lessThan":"bca61ee5192ea47003722486ae9588a2a4bb47b6","status":"affected","versionType":"git"},{"version":"4dd6f977fc778e5a0da604e5f8cb2f36d163d27b","lessThan":"db13064669526494cd78ba3a4394063b740e940c","status":"affected","versionType":"git"},{"version":"4dd6f977fc778e5a0da604e5f8cb2f36d163d27b","lessThan":"dcae1eeda53149f219dd6af93b3083b7271c1c63","status":"affected","versionType":"git"},{"version":"4dd6f977fc778e5a0da604e5f8cb2f36d163d27b","lessThan":"e533889fc26aea0cd83c90327063f272061dd820","status":"affected","versionType":"git"}]},{"product":"Linux","vendor":"Linux","defaultStatus":"affected","repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","programFiles":["fs/f2fs/file.c"],"versions":[{"version":"4.8","status":"affected"},{"version":"0","lessThan":"4.8","status":"unaffected","versionType":"semver"},{"version":"6.12.112","lessThanOrEqual":"6.12.*","status":"unaffected","versionType":"semver"},{"version":"6.18.53","lessThanOrEqual":"6.18.*","status":"unaffected","versionType":"semver"},{"version":"7.2.5","lessThanOrEqual":"7.2.*","status":"unaffected","versionType":"semver"},{"version":"7.3-rc1","lessThanOrEqual":"*","status":"unaffected","versionType":"original_commit_for_fix"}]}],"cpeApplicability":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"4.8","versionEndExcluding":"6.12.112"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"4.8","versionEndExcluding":"6.18.53"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"4.8","versionEndExcluding":"7.2.5"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"4.8","versionEndExcluding":"7.3-rc1"}]}]}],"references":[{"url":"https://git.kernel.org/stable/c/bca61ee5192ea47003722486ae9588a2a4bb47b6"},{"url":"https://git.kernel.org/stable/c/db13064669526494cd78ba3a4394063b740e940c"},{"url":"https://git.kernel.org/stable/c/dcae1eeda53149f219dd6af93b3083b7271c1c63"},{"url":"https://git.kernel.org/stable/c/e533889fc26aea0cd83c90327063f272061dd820"}],"title":"f2fs: validate MOVE_RANGE destination size","x_generator":{"engine":"bippy-1.2.0"}}}}