Bug 2541254 (CVE-2026-97534) - CVE-2026-97534 kernel: f2fs: accurately adjust free_sections during free_segment_range
Summary: CVE-2026-97534 kernel: f2fs: accurately adjust free_sections during free_segm...
Keywords:
Status: NEW
Alias: CVE-2026-97534
Product: Security Response
Classification: Other
Component: vulnerability
Version: unspecified
Hardware: All
OS: Linux
medium
medium
Target Milestone: ---
Assignee: Product Security DevOps Team
QA Contact:
URL:
Whiteboard:
Depends On:
Blocks:
TreeView+ depends on / blocked
 
Reported: 2026-09-25 11:11 UTC by OSIDB Bzimport
Modified: 2026-09-28 20:44 UTC (History)
17 users (show)

Fixed In Version:
Clone Of:
Environment:
Last Closed:
Embargoed:


Attachments (Terms of Use)

Description OSIDB Bzimport 2026-09-25 11:11:11 UTC
In the Linux kernel, the following vulnerability has been resolved:

f2fs: accurately adjust free_sections during free_segment_range

In free_segment_range(), MAIN_SECS(sbi) is temporarily reduced by `secs`
to restrict block allocation to the safe remaining main area while valid
blocks in the truncated range are evacuated by GC.

However, FREE_I(sbi)->free_sections tracks the total number of free
sections across the whole filesystem. If any sections within the
truncated range were already free upon entering free_segment_range(),
failing to deduct them from free_sections causes the filesystem to
overestimate available free sections in the active, reduced main area.
This leads to inconsistent free section accounting during GC data
migration and can trigger unexpected allocation failures or assertion
errors when space is tight.

Fix this by calculating the number of already-free sections in the
truncated range, deducting them from free_sections upon entering
free_segment_range(), and restoring them on exit.


Note You need to log in before you can comment on or make changes to this bug.