{"dataType":"CVE_RECORD","dataVersion":"5.2","cveMetadata":{"cveId":"CVE-2026-93816","assignerOrgId":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","state":"PUBLISHED","assignerShortName":"Linux","dateReserved":"2026-09-18T17:59:28.791Z","datePublished":"2026-09-24T16:02:53.171Z","dateUpdated":"2026-10-03T10:57:49.180Z"},"containers":{"cna":{"providerMetadata":{"orgId":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","shortName":"Linux","dateUpdated":"2026-10-03T10:57:49.180Z"},"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nf2fs: validate inline dentry name lengths before conversion\n\nInline dentry conversion copies names out of the inline dentry area\nbefore checking that each recorded name length fits in the available\nfilename slots.\n\nA corrupted image can therefore make the conversion path read past\nthe inline filename storage while building the regular dentry block.\n\nValidate each inline dentry name length against the inline filename\narea before copying it."}],"metrics":[{"cvssV3_1":{"version":"3.1","vectorString":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:H","baseScore":7.1,"baseSeverity":"HIGH"},"scenarios":[{"lang":"en","value":"AV:L - The oversized de->name_len is on-disk in the directory inode's inline dentry, not in a network PDU. creat/mkdir/rename reach the patched f2fs_add_inline_entries via f2fs_add_link→f2fs_add_inline_entry→do_convert_inline_dir→f2fs_move_rehashed_dirents (or f2fs_try_convert_inline_dir on same-dir rename); the syscall only supplies a normal filename that forces conversion.\nAC:L - The image sets i_dir_level nonzero (do_read_inode copies ri->i_dir_level with no range check, so conversion uses f2fs_move_rehashed_dirents), fills the inline bitmap so f2fs_room_for_filename fails, and plants a name_len that overruns remaining filename slots. The next creat(2) or recover_dentry add then hits the memcpy with no race.\nPR:N - Crafting the f2fs image takes no account or capability on the target. f2fs_add_inline_entries has no capable() gate; init-namespace CAP_SYS_ADMIN (f2fs_fs_type lacks FS_USERNS_MOUNT) is the victim's or automount helper's mount privilege, not the attacker's.\nUI:R - The bad name_len is only consumed after that image is mounted. A victim or trusted helper (udisks/vold) must mount it before f2fs_create/f2fs_rename or roll-forward recover_dentry→f2fs_add_dentry can call f2fs_add_inline_entries; automount does not make this a network bug.\nS:U - f2fs_update_dentry's over-read from backup_dentry and any oops stay in the host kernel that mounted the volume. This is not a KVM/Xen guest-to-host escape or an IOMMU/DMA boundary bypass.\nC:H - f2fs_add_inline_entries sets fname.disk_name.len from unvalidated de->name_len and f2fs_update_dentry memcpy's that many bytes from the kmalloc'd backup_dentry filename array. A name_len that still fits a regular dentry block (GET_DENTRY_SLOTS<=NR_DENTRY_IN_BLOCK, up to 1705) reads past MAX_INLINE_DATA into adjacent slab; those bytes become the converted name.\nI:N - f2fs_add_regular_entry only calls f2fs_update_dentry after f2fs_room_for_filename finds GET_DENTRY_SLOTS(name_len) free dest slots, so the memcpy stays inside the new 4K dentry folio. There is no kernel OOB write, UAF, or control-flow hijack; treating any heap over-read as I:H would apply to every infoleak.\nA:H - The same memcpy over-reads f2fs_kmalloc(MAX_INLINE_DATA) (~3KB) by up to ~1700 bytes, which can leave the slab object and oops on unmapped/poisoned memory during conversion, panicking or killing the task. A name_len whose slot count exceeds NR_DENTRY_IN_BLOCK also walks MAX_DIR_HASH_DEPTH allocating empty dir blocks before -ENOSPC."}]}],"affected":[{"product":"Linux","vendor":"Linux","defaultStatus":"unaffected","repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","programFiles":["fs/f2fs/inline.c"],"versions":[{"version":"675f10bde6cc3874632a8f684df2a8a2a8ace76e","lessThan":"6b5552449fc5acb8e6ecf045b46702b29b71165a","status":"affected","versionType":"git"},{"version":"675f10bde6cc3874632a8f684df2a8a2a8ace76e","lessThan":"6343208fd73f3f2b8044c0922185cd13ff807693","status":"affected","versionType":"git"},{"version":"675f10bde6cc3874632a8f684df2a8a2a8ace76e","lessThan":"4dd81faa63fd54b9ba1a83c304e6d0bd03f1898d","status":"affected","versionType":"git"},{"version":"675f10bde6cc3874632a8f684df2a8a2a8ace76e","lessThan":"aee4e6de71ca77626c006166ff00f1d01ff990c9","status":"affected","versionType":"git"},{"version":"675f10bde6cc3874632a8f684df2a8a2a8ace76e","lessThan":"2ce0bc5853bec7cdc724477a87ea579fde664243","status":"affected","versionType":"git"},{"version":"675f10bde6cc3874632a8f684df2a8a2a8ace76e","lessThan":"7caa8a0ae94b132576c2e46e9b4fd4e0f356f373","status":"affected","versionType":"git"},{"version":"675f10bde6cc3874632a8f684df2a8a2a8ace76e","lessThan":"cfcd0e49a178b3dac2c0ece656079081dbf5da74","status":"affected","versionType":"git"}]},{"product":"Linux","vendor":"Linux","defaultStatus":"affected","repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","programFiles":["fs/f2fs/inline.c"],"versions":[{"version":"4.7","status":"affected"},{"version":"0","lessThan":"4.7","status":"unaffected","versionType":"semver"},{"version":"5.10.271","lessThanOrEqual":"5.10.*","status":"unaffected","versionType":"semver"},{"version":"5.15.222","lessThanOrEqual":"5.15.*","status":"unaffected","versionType":"semver"},{"version":"6.1.189","lessThanOrEqual":"6.1.*","status":"unaffected","versionType":"semver"},{"version":"6.6.158","lessThanOrEqual":"6.6.*","status":"unaffected","versionType":"semver"},{"version":"6.12.111","lessThanOrEqual":"6.12.*","status":"unaffected","versionType":"semver"},{"version":"6.18.53","lessThanOrEqual":"6.18.*","status":"unaffected","versionType":"semver"},{"version":"7.2","lessThanOrEqual":"*","status":"unaffected","versionType":"original_commit_for_fix"}]}],"cpeApplicability":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"4.7","versionEndExcluding":"5.10.271"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"4.7","versionEndExcluding":"5.15.222"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"4.7","versionEndExcluding":"6.1.189"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"4.7","versionEndExcluding":"6.6.158"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"4.7","versionEndExcluding":"6.12.111"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"4.7","versionEndExcluding":"6.18.53"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"4.7","versionEndExcluding":"7.2"}]}]}],"references":[{"url":"https://git.kernel.org/stable/c/6b5552449fc5acb8e6ecf045b46702b29b71165a"},{"url":"https://git.kernel.org/stable/c/6343208fd73f3f2b8044c0922185cd13ff807693"},{"url":"https://git.kernel.org/stable/c/4dd81faa63fd54b9ba1a83c304e6d0bd03f1898d"},{"url":"https://git.kernel.org/stable/c/aee4e6de71ca77626c006166ff00f1d01ff990c9"},{"url":"https://git.kernel.org/stable/c/2ce0bc5853bec7cdc724477a87ea579fde664243"},{"url":"https://git.kernel.org/stable/c/7caa8a0ae94b132576c2e46e9b4fd4e0f356f373"},{"url":"https://git.kernel.org/stable/c/cfcd0e49a178b3dac2c0ece656079081dbf5da74"}],"title":"f2fs: validate inline dentry name lengths before conversion","x_generator":{"engine":"bippy-1.2.0"}}}}