SB20260925135 - Improper initialization in Linux kernel f2fs



SB20260925135 - Improper initialization in Linux kernel f2fs

Published: September 25, 2026

Security Bulletin ID SB20260925135
CSH Severity
Low
Patch available
YES
Number of vulnerabilities 1
Exploitation vector Local access
Highest impact Information disclosure

Breakdown by Severity

Low 100%
  • Low
  • Medium
  • High
  • Critical

Description

This security bulletin contains information about 1 vulnerability.


1) Improper initialization (CVE-ID: CVE-2026-93235)

CWE-ID: CWE-665 - Improper Initialization

CVSSv4: 2 [CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a local user to disclose sensitive information.

The vulnerability exists due to improper initialization of post-EOF data in the F2FS file size extension handling when extending a file across an unaligned EOF boundary. A local user can extend a file across an unaligned EOF boundary to disclose sensitive information.

Stale disk data can be exposed after remounting or crash recovery when metadata is persisted before the zeroed data.


Remediation

Install update from vendor's website.