Instituto Nacional de ciberseguridad. Sección Incibe
Instituto Nacional de Ciberseguridad. Sección INCIBE-CERT

CVE-2026-63817

Gravedad:
Pendiente de análisis
Tipo:
No Disponible / Otro tipo
Fecha de publicación:
19/07/2026
Última modificación:
19/07/2026

Descripción

*** Pendiente de traducción *** In the Linux kernel, the following vulnerability has been resolved:<br /> <br /> f2fs: validate compress cache inode only when enabled<br /> <br /> F2FS_COMPRESS_INO() uses NM_I(sbi)-&gt;max_nid as the synthetic inode<br /> number for the compressed page cache inode. That inode only exists when<br /> the compress_cache mount option is enabled.<br /> <br /> When compress_cache is disabled, max_nid is outside the valid inode<br /> range. A corrupted directory entry that points to ino == max_nid should<br /> therefore be rejected by f2fs_check_nid_range(). However, is_meta_ino()<br /> currently treats F2FS_COMPRESS_INO() as a meta inode unconditionally,<br /> so f2fs_iget() bypasses do_read_inode() and its nid range check, and<br /> instantiates a fake internal inode instead.<br /> <br /> Gate the compressed cache inode case on COMPRESS_CACHE, matching<br /> f2fs_init_compress_inode(). With compress_cache disabled, ino ==<br /> max_nid now follows the normal inode path and is rejected as an<br /> out-of-range nid.

Impacto