Review reviewHigh

CVE-2026-63818

Linux

In the Linux kernel, the following vulnerability has been resolved: f2fs: validate orphan inode entry count f2fs_recover_orphan_inodes() trusts the orphan block entry_count when replaying orphan inodes from the checkpoint pack. A corrupted entry_count larger than F2FS_ORPHANS_PER_BLOCK makes the recovery loop read past the ino[] array and interpret footer or following data as inode numbers. On a crafted image, mounting an unpatched kernel can drive orphan recovery into f2fs_bug_on() and panic the kernel. Validate entry_count before consuming entries so corrupted checkpoint data fails the mo...

CVSS
8.4
EPSS
-
- percentile
CISA KEV
Not listed
Published
2026.07.19
PRIORITY ASSESSMENT

Review review

The CVSS severity warrants an early asset and exposure review.

Known exploitationNot established by KEV
Exploit probability-
Technical severityCVSS 8.4

Vulnerability overview

In the Linux kernel, the following vulnerability has been resolved: f2fs: validate orphan inode entry count f2fs_recover_orphan_inodes() trusts the orphan block entry_count when replaying orphan inodes from the checkpoint pack. A corrupted entry_count larger than F2FS_ORPHANS_PER_BLOCK makes the recovery loop read past the ino[] array and interpret footer or following data as inode numbers. On a crafted image, mounting an unpatched kernel can drive orphan recovery into f2fs_bug_on() and panic the kernel. Validate entry_count before consuming entries so corrupted checkpoint data fails the mo...

Affected product and versions

Product
Linux
Affected versions
>= 127e670abfa7fa150f6550d620ded930f5bdb4e7 < 210c210c92d78fdf5051bc55c5c69044b1a2150a, >= 127e670abfa7fa150f6550d620ded930f5bdb4e7 < ad101d15716f5a24d1fa82a849f80430c805a3dd, >= 127e670abfa7fa150f6550d620ded930f5bdb4e7 < d18c81f5d0ecd5796aa47d66d98f2dd54d8d0f70, >= 127e670abfa7fa150f6550d620ded930f5bdb4e7 < d2f236196d542ccd8505736e41c3a1d3f0305f6f, >= 127e670abfa7fa150f6550d620ded930f5bdb4e7 < 550511a2470f6d204fa07b331f048bd2d3c51280, >= 127e670abfa7fa150f6550d620ded930f5bdb4e7 < 8aad54746c251f2c2370118df766c0c82e2d2091, >= 127e670abfa7fa150f6550d620ded930f5bdb4e7 < 2e12381d4495dc8b0ff042c6856022b2e359835c, >= 127e670abfa7fa150f6550d620ded930f5bdb4e7 < 846c499a65816d13f1186e3090e825e8bb8bcb8b, >= 3.8
Fixed versions
No verified fixed-version field is available yet

Recommended response sequence

Confirm exposure before applying a vendor-supported change.

Full remediation guide
  1. 1
    Identify

    Confirm that Linux and an affected version are present.

  2. 2
    Prioritize

    Combine exploitation signals with asset exposure and business criticality.

  3. 3
    Remediate

    Follow the vendor advisory or supported update path and preserve rollback options.

  4. 4
    Verify

    Recheck the version, service health, access paths, and relevant logs.

Technical data

CVSS vector
CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CWE
Not available