Unrated severityNVD Advisory· Published Sep 16, 2026
CVE-2026-89838
CVE-2026-89838
Description
In the Linux kernel, the following vulnerability has been resolved:
f2fs: limit recovery filename logging to stored length
F2FS stores recovery filenames as a length plus a fixed-size i_name buffer. The buffer is not NUL-terminated, but recover_inode() and recover_dentry() print it with %s.
For a 255-byte filename, recovery logging can read past i_name into the following raw inode fields.
Print the name with a precision bounded by i_namelen and F2FS_NAME_LEN.
Affected products
1Patches
Vulnerability mechanics
References
2News mentions
0No linked articles in our index yet.