Improper Check or Handling of Exceptional Conditions in Linux kernel - CVE-2026-63820

 

Improper Check or Handling of Exceptional Conditions in Linux kernel - CVE-2026-63820

Published: July 21, 2026


Vulnerability identifier: #VU138827
CSH Severity: Low
CVSS v4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2026-63820
CWE-ID: CWE-703
Exploitation vector: Local access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a local user to cause a denial of service.

The vulnerability exists due to improper error handling in f2fs_read_data_large_folio() when processing large folio readahead after an error condition. A local user can trigger an error during file read operations to cause a denial of service.

Pending read completion can be left unsignaled for earlier folios, which may cause readers to wait indefinitely on locked folios.


Affected software

Linux kernel

How to mitigate CVE-2026-63820

Install security update from vendor's repository.

Linux kernel - update to 7.0 rc3

External References

Related Security Bulletins