NULL pointer dereference in Linux kernel - CVE-2026-63811
Published: July 21, 2026
Vulnerability details
The vulnerability allows a local user to cause a denial of service.
The vulnerability exists due to a null pointer dereference in f2fs atomic write handling when reading COW data during write-begin processing. A local user can update an atomic-write file in a crafted encryption-policy state to cause a denial of service.
The issue occurs when the original inode and its COW inode use different encryption contexts, causing decryption to be attempted on a folio owned by the original inode.