Out-of-bounds read in Linux kernel - CVE-2026-53303
Published: June 29, 2026
Linux kernel
Detailed vulnerability description
The vulnerability allows a local user to cause a denial of service.
The vulnerability exists due to an out-of-bounds read in f2fs_sbi_show() when reading the extension_list during sysfs access concurrent with extension list updates. A local user can trigger concurrent sysfs operations to cause a denial of service.
The issue may also result in stale data being displayed.
How to mitigate CVE-2026-53303
Sources
- https://git.kernel.org/stable/c/4b3a1bf4c2ffd4c9595d900ead78c9035894a025
- https://git.kernel.org/stable/c/5909bedbed38c558bee7cb6758ceedf9bc3a9194
- https://git.kernel.org/stable/c/cea15f66b7b68b2c50943a6660e0692c6635e4eb
- https://git.kernel.org/stable/c/d0e877810baf613b018fd9747440b9d4d9db1428
- https://git.kernel.org/stable/c/d3ff0c121bbaef026df6248ab7ef6f0b068b0647
- https://git.kernel.org/stable/c/ea3ab43a1f3cf2c7cecd75c8be1ee99a5e94a92e