PT-2026-97902 · Linux · Linux Kernel
CVE-2026-93235
·
Published
2026-09-24
·
Updated
2026-09-28
None
No severity ratings or metrics are available. When they are, we'll update the corresponding info on the page.
Name of the Vulnerable Software and Affected Versions
Linux kernel (affected versions not specified)
Description
An issue exists in the f2fs filesystem where extending a file size across an unaligned EOF (End of File) boundary—via operations such as truncate, fallocate, or write—may fail to properly zero out post-EOF data in the partial page within the pagecache. If this data is not zeroed and marked dirty before the inode is committed with an updated
i size, stale disk data beyond the previous EOF can be exposed after a system crash recovery or remounting. This occurs because the system must ensure that the cache is written back to persist the zeroed data.Recommendations
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Use the
fsync mode=strict mount option to mitigate the risk of stale data exposure.Exploit
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Linux Kernel