CVE-2026-63812
Last modified
CVE-2026-63812 is a high-severity vulnerability rated 7.8/10 on the CVSS scale. In the Linux kernel, the following vulnerability has been resolved: f2fs: fix incorrect FI_NO_EXTENT handling in __destroy_extent_node() When __destroy_extent_node() sets the inode flag FI_NO_EXTENT, it does not reset the length of the largest extent to 0 and update the inode folio. Since modifications to the extent tree are disallowed afterward, the cached largest extent may become stale. EPSS estimates a 0.12% chance of exploitation in the next 30 days.
Description
In the Linux kernel, the following vulnerability has been resolved: f2fs: fix incorrect FI_NO_EXTENT handling in __destroy_extent_node() When __destroy_extent_node() sets the inode flag FI_NO_EXTENT, it does not reset the length of the largest extent to 0 and update the inode folio. Since modifications to the extent tree are disallowed afterward, the cached largest extent may become stale. This can trigger the following error in xfstests generic/388: F2FS-fs (dm-0): sanity_check_extent_cache: inode (ino=1761) extent info [220057, 57, 6] is incorrect, run fsck to fix In the f2fs_drop_inode path, __destroy_extent_node() does not need to guarantee that et->node_cnt is 0, because concurrency with writeback is expected in this path, and writeback may update the extent cache. This patch reverts commit ed78aeebef05 ("f2fs: fix node_cnt race between extent node destroy and writeback"), and remove the unnecessary zero check of et->node_cnt.
Metrics
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Affected Software
Source: CNA advisory (CVE.org). NVD analysis pending.
| Vendor | Product | Versions |
|---|---|---|
| Linux | Linux | >= 42dd1c91f993431d0b399502479d00e6ad1bca71, < 7e4d8f98be63f98856a5176b9188dada6e7ba9ee; >= ab1eaf9d5c99042f5b0243bf67a06283a4c0757f, < 58a5deb220bcac4c73bf58954c0845644c997487; >= b0e4395870eb3441ddc959f6710b5f6ca61aff26, < 20190e498057997532c7f186d081011f18e0a462; >= ed78aeebef05212ef7dca93bd931e4eff67c113f, < edf12cbeeeabe799bd2ee21fdb5c336cce6fbad7; >= ed78aeebef05212ef7dca93bd931e4eff67c113f, < 1f70ddb28a3c71df124da5fa4040c808116d6bb9; 0559a0e962aacbb47519e26ee663be04b72dcb92; >= 6.6.140, < 6.6.144; >= 6.12.88, < 6.12.95; >= 6.18.30, < 6.18.38; >= 7.0.7, < 7.1 |
| Linux | Linux | 7.1 |
References
Timeline
- Published
- Last Modified
- Status
- Awaiting Analysis
Frequently Asked Questions
What is CVE-2026-63812?
How severe is CVE-2026-63812?
How do I fix CVE-2026-63812?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2026
- CVE-2026-63807In the Linux kernel, the following vulnerability has been re…8.8
- CVE-2026-63808In the Linux kernel, the following vulnerability has been re…9.8
- CVE-2026-63809In the Linux kernel, the following vulnerability has been re…7.8
- CVE-2026-6381The WP Maps WordPress plugin before 4.9.3 does not properly…7.5
- CVE-2026-63810In the Linux kernel, the following vulnerability has been re…
- CVE-2026-63811In the Linux kernel, the following vulnerability has been re…
- CVE-2026-63813In the Linux kernel, the following vulnerability has been re…7.8
- CVE-2026-63814In the Linux kernel, the following vulnerability has been re…7.8
- CVE-2026-63815In the Linux kernel, the following vulnerability has been re…8.4
- CVE-2026-63816In the Linux kernel, the following vulnerability has been re…7.8
- CVE-2026-63817In the Linux kernel, the following vulnerability has been re…7.8
- CVE-2026-63818In the Linux kernel, the following vulnerability has been re…8.4
Are you affected by CVE-2026-63812?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
