CVE-2025-71107: f2fs: ensure node page reads complete before f2fs_put_super() finishes

Published Jan 14, 2026
·
Updated

In the Linux kernel, the following vulnerability has been resolved:

f2fs: ensure node page reads complete before f2fsputsuper() finishes

Xfstests generic/335, generic/336 sometimes crash with the following message:

F2FS-fs (dm-0): detect filesystem reference count leak during umount, type: 9, count: 1 ------------[ cut here ]------------ kernel BUG at fs/f2fs/super.c:1939! Oops: invalid opcode: 0000 [#1] SMP NOPTI CPU: 1 UID: 0 PID: 609351 Comm: umount Tainted: G W 6.17.0-rc5-xfstests-g9dd1835ecda5 #1 PREEMPT(none) Tainted: [W]=WARN Hardware name: QEMU Standard PC (Q35 + ICH9, 2009), BIOS 1.16.3-debian-1.16.3-2 04/01/2014 RIP: 0010:f2fsputsuper+0x3b3/0x3c0 Call Trace: <TASK> genericshutdownsuper+0x7e/0x190 killblocksuper+0x1a/0x40 killf2fssuper+0x9d/0x190 deactivatelockedsuper+0x30/0xb0 cleanupmnt+0xba/0x150 taskworkrun+0x5c/0xa0 exittousermodeloop+0xb7/0xc0 dosyscall64+0x1ae/0x1c0 entrySYSCALL64afterhwframe+0x76/0x7e </TASK> ---[ end trace 0000000000000000 ]---

It appears that sometimes it is possible that f2fsputsuper() is called before all node page reads are completed. Adding a call to f2fswaitonallpages() for F2FSRDNODE fixes the problem.

Affected Software

14 affected components
Linux Linux kernel
Linux Linux kernel>=6.4.16<6.5
Linux Linux kernel>=6.5.1<6.6.120
Linux Linux kernel>=6.7<6.12.64
Linux Linux kernel>=6.13<6.18.3
Linux Linux kernel=6.5
Linux Linux kernel=6.19-rc1
Linux Linux kernel=6.19-rc2
Linux Linux kernel=6.19-rc3
Linux Linux kernel=6.19-rc4
Linux Linux kernel=6.19-rc5
Linux Linux kernel=6.19-rc6
Linux Linux kernel=6.19-rc7
Linux Linux kernel=6.19-rc8

Event History

Jan 14, 2026
CVE Published
via MITRE·03:05 PM
Data Sourced
via MITRE·03:05 PM
Description
Data Sourced
via NVD·03:15 PM
RemedyDescriptionSeverityWeaknessAffected Software

Frequently Asked Questions

1

What is the severity of CVE-2025-71107?

CVE-2025-71107 has been classified as a medium severity vulnerability affecting the Linux kernel.

2

How do I fix CVE-2025-71107?

To fix CVE-2025-71107, update to the latest version of the Linux kernel that includes the security patch for this vulnerability.

3

What systems are affected by CVE-2025-71107?

CVE-2025-71107 affects the Linux kernel, specifically in configurations using the F2FS filesystem.

4

What is the impact of CVE-2025-71107?

The impact of CVE-2025-71107 includes potential crashes and instability during certain filesystem operations.

5

When was CVE-2025-71107 disclosed?

CVE-2025-71107 was disclosed as part of a security update for the Linux kernel, addressing critical filesystem issues.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203