PT-2026-97902 · Linux · Linux Kernel

CVE-2026-93235

·

Published

2026-09-24

·

Updated

2026-09-28

None

No severity ratings or metrics are available. When they are, we'll update the corresponding info on the page.
Name of the Vulnerable Software and Affected Versions Linux kernel (affected versions not specified)
Description An issue exists in the f2fs filesystem where extending a file size across an unaligned EOF (End of File) boundary—via operations such as truncate, fallocate, or write—may fail to properly zero out post-EOF data in the partial page within the pagecache. If this data is not zeroed and marked dirty before the inode is committed with an updated i size, stale disk data beyond the previous EOF can be exposed after a system crash recovery or remounting. This occurs because the system must ensure that the cache is written back to persist the zeroed data.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability. Use the fsync mode=strict mount option to mitigate the risk of stale data exposure.

Exploit

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2026-93235
OPENSUSE-SU-2026:11893-1

Affected Products

Linux Kernel