CVE-2026-93816: f2fs: validate inline dentry name lengths before conversion

Published Sep 24, 2026
·
Updated

In the Linux kernel, the following vulnerability has been resolved:

f2fs: validate inline dentry name lengths before conversion

Inline dentry conversion copies names out of the inline dentry area before checking that each recorded name length fits in the available filename slots.

A corrupted image can therefore make the conversion path read past the inline filename storage while building the regular dentry block.

Validate each inline dentry name length against the inline filename area before copying it.

Affected Software

1 affected component
Linux Linux kernel

Event History

Sep 24, 2026
CVE Published
via MITRE·04:02 PM
Data Sourced
via MITRE·04:02 PM
Description
Data Sourced
via NVD·05:17 PM
DescriptionSeverity

Frequently Asked Questions

1

Who is realistically exposed to this issue?

Systems that mount or process a corrupted F2FS filesystem image are exposed when the inline dentry conversion path is reached. The issue is in the Linux kernel's F2FS handling rather than in ordinary filename processing alone.

2

What does an attacker need to exploit it?

An attacker needs to provide or cause use of a corrupted F2FS image containing inline dentries with recorded name lengths that exceed the available inline filename storage. Exploitation requires the kernel to perform inline dentry conversion on that filesystem data.

3

How can I determine whether a filesystem image is affected?

Inspect the image's inline dentries for recorded filename lengths that do not fit within the available inline filename slots. An affected image contains malformed length values that would cause conversion to copy beyond inline filename storage.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203