CVE-2026-63816

Source
https://cve.org/CVERecord?id=CVE-2026-63816
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-63816.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2026-63816
Downstream
Related
Published
2026-07-19T12:02:15Z
Modified
2026-10-08T02:51:28Z
Severity
  • 7.8 (High) CVSS_V3 - CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H CVSS Calculator
Summary
f2fs: atomic: fix UAF issue on f2fs_inode_info.atomic_inode
Details

In the Linux kernel, the following vulnerability has been resolved:

f2fs: atomic: fix UAF issue on f2fs_inode_info.atomic_inode

  • ioctl(F2FS_IOC_GARBAGE_COLLECT_RANGE) - shrink
  • f2fs_gc
  • gc_data_segment
  • ra_data_block(cow_inode) - mapping = F2FS_I(inode)->atomic_inode->i_mapping : f2fs_is_cow_file(cow_inode) is true - f2fs_evict_inode(atomic_inode) - clear_inode_flag(fi->cow_inode, FI_COW_FILE) - F2FS_I(fi->cow_inode)->atomic_inode = NULL ... - truncate_inode_pages_final(atomic_inode) - f2fs_grab_cache_folio(mapping) : create folio in atomic_inode->mapping - clear_inode(atomic_inode) - BUG_ON(atomic_inode->i_data.nrpages)

We need to add a reference on fi->atomic_inode before using its mapping field during garbage collection, otherwise, it will cause UAF issue.

Database specific
{
    "cna_assigner": "Linux",
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/63xxx/CVE-2026-63816.json"
}
References

Affected packages

Git / git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git

Affected ranges

Type
GIT
Repo
https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git
Events
Introduced
3db1de0e582c358dd013f3703cd55b5fe4076436
Fixed
7d3ae21783e5914c1761ac7d63f882d3d70800e9
Fixed
56038756aae68312df00d4aa1d97e51ef3aca725
Fixed
a499f77c06050a28c897bdbd86cd2f0721ae0743
Fixed
a805fec35c201c59643ddcde713bce4051c8ee27
Fixed
e0288584baa5dc41df4a829a023c4c1b33fe53d7
Type
GIT
Repo
https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git
Events
Introduced
5.18.18
Fixed
5.19
Type
GIT
Repo
https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git
Events
Introduced
6db52f1944417c2601182a591a704e2f119c5215

Affected versions

v5.*
v5.18.18
v5.18.19

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-63816.json"

Linux / Kernel

Package

Name
Kernel

Affected ranges

Type
ECOSYSTEM
Events
Introduced
5.19.0
Fixed
6.6.145
Type
ECOSYSTEM
Events
Introduced
6.7.0
Fixed
6.12.96
Type
ECOSYSTEM
Events
Introduced
6.13.0
Fixed
6.18.39
Type
ECOSYSTEM
Events
Introduced
6.19.0
Fixed
7.1.3

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-63816.json"