{"api_version":"1","generated_at":"2026-09-21T09:20:16+00:00","cve":"CVE-2026-89832","urls":{"html":"https://cve.report/CVE-2026-89832","api":"https://cve.report/api/cve/CVE-2026-89832.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2026-89832","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2026-89832"},"summary":{"title":"f2fs: fix to clear dirty flag on folio in error path","description":"In the Linux kernel, the following vulnerability has been resolved:\n\nf2fs: fix to clear dirty flag on folio in error path\n\nIf node block is corrupted due to chksum mismatch or inconsistent\nfooter info, it needs to drop clear flag of node folio, in order\nto persist inconsistent node data to storage.","state":"PUBLISHED","assigner":"Linux","published_at":"2026-09-16 11:16:49","updated_at":"2026-09-16 15:18:12"},"problem_types":[],"metrics":[{"version":"3.1","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","score":"7.8","severity":"HIGH","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","data":{"version":"3.1","vectorString":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","baseScore":7.8,"baseSeverity":"HIGH","attackVector":"LOCAL","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH"}},{"version":"3.1","source":"CNA","type":"DECLARED","score":"7.8","severity":"HIGH","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","data":{"baseScore":7.8,"baseSeverity":"HIGH","vectorString":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","version":"3.1"}}],"references":[{"url":"https://git.kernel.org/stable/c/3923ec2b98c96dda4a8bfab81d22553dbf0dd6c2","name":"https://git.kernel.org/stable/c/3923ec2b98c96dda4a8bfab81d22553dbf0dd6c2","refsource":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","tags":[],"title":"","mime":"","httpstatus":"","archivestatus":"0"},{"url":"https://git.kernel.org/stable/c/5b86eab84ac8e9289b5afc52ef88ab18ba5bacab","name":"https://git.kernel.org/stable/c/5b86eab84ac8e9289b5afc52ef88ab18ba5bacab","refsource":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","tags":[],"title":"","mime":"","httpstatus":"","archivestatus":"0"},{"url":"https://git.kernel.org/stable/c/ab35ae07f2b5b4e118ea47b88577fc7d0e797b17","name":"https://git.kernel.org/stable/c/ab35ae07f2b5b4e118ea47b88577fc7d0e797b17","refsource":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","tags":[],"title":"","mime":"","httpstatus":"","archivestatus":"0"},{"url":"https://www.cve.org/CVERecord?id=CVE-2026-89832","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2026-89832","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[{"source":"CNA","vendor":"Linux","product":"Linux","version":"affected b42b179bda9ff11075a6fc2bac4d9e400513679a ab35ae07f2b5b4e118ea47b88577fc7d0e797b17 git","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"affected b42b179bda9ff11075a6fc2bac4d9e400513679a 3923ec2b98c96dda4a8bfab81d22553dbf0dd6c2 git","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"affected b42b179bda9ff11075a6fc2bac4d9e400513679a 5b86eab84ac8e9289b5afc52ef88ab18ba5bacab git","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"affected 8d7ebdd109b4654ec5e0e9c3c6f08b06d6558f10 git","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"affected b039536485970829918aa237a08417bd0ed5437c git","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"affected 4.19.51 4.20 semver","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"affected 5.1.10 5.2 semver","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"affected 5.2","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"unaffected 5.2 semver","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"unaffected 6.18.51 6.18.* semver","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"unaffected 7.2.5 7.2.* semver","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"unaffected 7.3-rc1 * original_commit_for_fix","platforms":[]}],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[],"vendor_comments":[],"enrichments":{"kev":null,"epss":null,"legacy_qids":[]},"source_records":{"cve_program":{"containers":{"cna":{"affected":[{"defaultStatus":"unaffected","product":"Linux","programFiles":["fs/f2fs/node.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","vendor":"Linux","versions":[{"lessThan":"ab35ae07f2b5b4e118ea47b88577fc7d0e797b17","status":"affected","version":"b42b179bda9ff11075a6fc2bac4d9e400513679a","versionType":"git"},{"lessThan":"3923ec2b98c96dda4a8bfab81d22553dbf0dd6c2","status":"affected","version":"b42b179bda9ff11075a6fc2bac4d9e400513679a","versionType":"git"},{"lessThan":"5b86eab84ac8e9289b5afc52ef88ab18ba5bacab","status":"affected","version":"b42b179bda9ff11075a6fc2bac4d9e400513679a","versionType":"git"},{"status":"affected","version":"8d7ebdd109b4654ec5e0e9c3c6f08b06d6558f10","versionType":"git"},{"status":"affected","version":"b039536485970829918aa237a08417bd0ed5437c","versionType":"git"},{"lessThan":"4.20","status":"affected","version":"4.19.51","versionType":"semver"},{"lessThan":"5.2","status":"affected","version":"5.1.10","versionType":"semver"}]},{"defaultStatus":"affected","product":"Linux","programFiles":["fs/f2fs/node.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","vendor":"Linux","versions":[{"status":"affected","version":"5.2"},{"lessThan":"5.2","status":"unaffected","version":"0","versionType":"semver"},{"lessThanOrEqual":"6.18.*","status":"unaffected","version":"6.18.51","versionType":"semver"},{"lessThanOrEqual":"7.2.*","status":"unaffected","version":"7.2.5","versionType":"semver"},{"lessThanOrEqual":"*","status":"unaffected","version":"7.3-rc1","versionType":"original_commit_for_fix"}]}],"cpeApplicability":[{"nodes":[{"cpeMatch":[{"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionEndExcluding":"6.18.51","versionStartIncluding":"5.2","vulnerable":true},{"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionEndExcluding":"7.2.5","versionStartIncluding":"5.2","vulnerable":true},{"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionEndExcluding":"7.3-rc1","versionStartIncluding":"5.2","vulnerable":true},{"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"4.19.51","vulnerable":true},{"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"5.1.10","vulnerable":true}],"negate":false,"operator":"OR"}]}],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nf2fs: fix to clear dirty flag on folio in error path\n\nIf node block is corrupted due to chksum mismatch or inconsistent\nfooter info, it needs to drop clear flag of node folio, in order\nto persist inconsistent node data to storage."}],"metrics":[{"cvssV3_1":{"baseScore":7.8,"baseSeverity":"HIGH","vectorString":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","version":"3.1"},"scenarios":[{"lang":"en","value":"AV:L - __get_node_folio is reached only through local VFS operations (lookup, open, read/write, fallocate, fsync, GC) on a mounted f2fs volume such as Android userdata or removable flash; it is not a ksmbd/nfsd/packet-processing path.\nAC:L - A crafted f2fs image lets the attacker pick node footers and nids so a dirty direct-node folio is later re-fetched as NODE_TYPE_INODE (or fails checksum) on ordinary file ops; triggering is deterministic with no race or rare config.\nPR:L - After automount (Android vold/udisks2 portable f2fs) or on already-mounted userdata, any unprivileged user with file access reaches __get_node_folio via write then lookup; no CAP_SYS_ADMIN is needed on that syscall path.\nUI:N - The attacker dirties the node and then looks up the type-confused nid themselves; removable f2fs is commonly auto-mounted and scanned without a separate victim mount or open step.\nS:U - Dirty-flag mishandling, persisted node metadata, and any page-cache fallout remain in the host kernel's authority; this is not a VM escape, container breakout, or IOMMU bypass.\nC:H - A still-dirty corrupted node folio can be written back with inconsistent mappings, and a later read_node_folio will read into that dirty folio; file offsets can then resolve to other files' or leftover blocks and disclose their contents.\nI:H - Writeback of the leftover dirty node persists inconsistent footer/checksum metadata, and the subsequent read into a dirty folio overwrites in-memory node contents from disk, corrupting block maps in an attacker-influenced way.\nA:H - Footer failure on a still-dirty node stops checkpoint (and panics with errors=panic), can leak F2FS_DIRTY_NODES so checkpoint retries hang, and dirty !uptodate node folios can oops or freeze filesystem I/O."}]}],"providerMetadata":{"dateUpdated":"2026-09-16T14:39:06.994Z","orgId":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","shortName":"Linux"},"references":[{"url":"https://git.kernel.org/stable/c/ab35ae07f2b5b4e118ea47b88577fc7d0e797b17"},{"url":"https://git.kernel.org/stable/c/3923ec2b98c96dda4a8bfab81d22553dbf0dd6c2"},{"url":"https://git.kernel.org/stable/c/5b86eab84ac8e9289b5afc52ef88ab18ba5bacab"}],"title":"f2fs: fix to clear dirty flag on folio in error path","x_generator":{"engine":"bippy-1.2.0"}}},"cveMetadata":{"assignerOrgId":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","assignerShortName":"Linux","cveId":"CVE-2026-89832","datePublished":"2026-09-16T10:31:04.691Z","dateReserved":"2026-09-11T19:38:34.769Z","dateUpdated":"2026-09-16T14:39:06.994Z","state":"PUBLISHED"},"dataType":"CVE_RECORD","dataVersion":"5.2"},"nvd":{"publishedDate":"2026-09-16 11:16:49","lastModifiedDate":"2026-09-16 15:18:12","problem_types":[],"metrics":{"cvssMetricV31":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","baseScore":7.8,"baseSeverity":"HIGH","attackVector":"LOCAL","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH"},"exploitabilityScore":1.8,"impactScore":5.9}]},"configurations":[]},"legacy_mitre":{"record":{"CveYear":"2026","CveId":"89832","Ordinal":"1","Title":"f2fs: fix to clear dirty flag on folio in error path","CVE":"CVE-2026-89832","Year":"2026"},"notes":[{"CveYear":"2026","CveId":"89832","Ordinal":"1","NoteData":"In the Linux kernel, the following vulnerability has been resolved:\n\nf2fs: fix to clear dirty flag on folio in error path\n\nIf node block is corrupted due to chksum mismatch or inconsistent\nfooter info, it needs to drop clear flag of node folio, in order\nto persist inconsistent node data to storage.","Type":"Description","Title":"f2fs: fix to clear dirty flag on folio in error path"}]}}}