PT-2026-61128 · Linux+1 · Linux Kernel+1

CVE-2026-63812

·

Published

2026-07-19

·

Updated

2026-09-07

CVSS v3.1

7.8

High

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Linux kernel (affected versions not specified)
Description An issue exists in the f2fs component where the destroy extent node() function incorrectly handles the FI NO EXTENT inode flag. When this flag is set, the function fails to reset the length of the largest extent to 0 and does not update the inode folio. Because subsequent modifications to the extent tree are prohibited, the cached largest extent can become stale, potentially leading to incorrect extent information and system errors.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2026-63812
OPENSUSE-SU-2026:11339-1
USN-8726-1
USN-8727-1

Affected Products

Linux Kernel
Ubuntu