SB20260925135 - Improper initialization in Linux kernel f2fs
Published: September 25, 2026
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 1 vulnerability.
1) Improper initialization (CVE-ID: CVE-2026-93235)
CWE-ID: CWE-665 - Improper Initialization
CVSSv4: 2 [CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a local user to disclose sensitive information.
The vulnerability exists due to improper initialization of post-EOF data in the F2FS file size extension handling when extending a file across an unaligned EOF boundary. A local user can extend a file across an unaligned EOF boundary to disclose sensitive information.
Stale disk data can be exposed after remounting or crash recovery when metadata is persisted before the zeroed data.
Remediation
Install update from vendor's website.
References
- https://git.kernel.org/stable/c/32c7f11a24268ba8d3bb50ea7f54d33f698cd253
- https://git.kernel.org/stable/c/5eced87b7d19dbc76ebdddaf322046f9ac582fcb
- https://git.kernel.org/stable/c/6882d458d2e403f6ba7b45542dd31a6b7531eb2e
- https://git.kernel.org/stable/c/91ec55ddc097ccddd25ffb95a3d079b2ef362372
- https://git.kernel.org/stable/c/c42608c09b6b5d5967bf211c255914c068c2cde1