« Volver al listado

CVE-2026-89839

Estado: RecibidaSin puntuar—

In the Linux kernel, the following vulnerability has been resolved:

f2fs: use the mount idmap for the owner check in f2fs_xattr_advise_set()

f2fs_xattr_advise_set() calls inode_owner_or_capable() with &nop_mnt_idmap before allowing the "system.advise" xattr to be set, instead of the idmap that the VFS passes to the ->set() handler.

f2fs supports idmapped mounts, so on such a mount this checks the caller's fsuid against the unmapped on-disk owner rather than the mapped owner: the actual owner can be wrongly denied with -EPERM and an unrelated caller wrongly allowed. Pass the handler's idmap instead.

CVSS

NVD no ha asignado puntuación CVSS a esta CVE (habitual desde el cambio de política de abril de 2026).

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (1)

⚠ Inferidas por IA a partir de la descripción — NVD aún no ha analizado esta CVE; no son CPE verificados.

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2026-89839",
  "cveTags": [],
  "metrics": {},
  "affected": [
    {
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
      "affectedData": [
        {
          "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
          "vendor": "Linux",
          "product": "Linux",
          "versions": [
            {
              "status": "affected",
              "version": "01beba7957a26f9b7179127e8ad56bb5a0f56138",
              "lessThan": "4c0c610b480cfbc57528aa1acbd6be12ed2a6fb1",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "01beba7957a26f9b7179127e8ad56bb5a0f56138",
              "lessThan": "c3e2692c7a58e0bdb84bd658d827e89dcecea3ad",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "01beba7957a26f9b7179127e8ad56bb5a0f56138",
              "lessThan": "3b681229e9f8fb1dd29bc65983bf3c87779e4ca3",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "01beba7957a26f9b7179127e8ad56bb5a0f56138",
              "lessThan": "ab31e3b774f5d06b4489cef6c297b48c47c9dcbd",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "01beba7957a26f9b7179127e8ad56bb5a0f56138",
              "lessThan": "a54ffce4637acb0db8e695188a6c7f99f14c3576",
              "versionType": "git"
            }
          ],
          "programFiles": [
            "fs/f2fs/xattr.c"
          ],
          "defaultStatus": "unaffected"
        },
        {
          "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
          "vendor": "Linux",
          "product": "Linux",
          "versions": [
            {
              "status": "affected",
              "version": "6.3"
            },
            {
              "status": "unaffected",
              "version": "0",
              "lessThan": "6.3",
              "versionType": "semver"
            },
            {
              "status": "unaffected",
              "version": "6.6.157",
              "versionType": "semver",
              "lessThanOrEqual": "6.6.*"
            },
            {
              "status": "unaffected",
              "version": "6.12.110",
              "versionType": "semver",
              "lessThanOrEqual": "6.12.*"
            },
            {
              "status": "unaffected",
              "version": "6.18.51",
              "versionType": "semver",
              "lessThanOrEqual": "6.18.*"
            },
            {
              "status": "unaffected",
              "version": "7.2.5",
              "versionType": "semver",
              "lessThanOrEqual": "7.2.*"
            },
            {
              "status": "unaffected",
              "version": "7.3-rc1",
              "versionType": "original_commit_for_fix",
              "lessThanOrEqual": "*"
            }
          ],
          "programFiles": [
            "fs/f2fs/xattr.c"
          ],
          "defaultStatus": "affected"
        }
      ]
    }
  ],
  "published": "2026-09-16T11:16:50.727",
  "references": [
    {
      "url": "https://git.kernel.org/stable/c/3b681229e9f8fb1dd29bc65983bf3c87779e4ca3",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/4c0c610b480cfbc57528aa1acbd6be12ed2a6fb1",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/a54ffce4637acb0db8e695188a6c7f99f14c3576",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/ab31e3b774f5d06b4489cef6c297b48c47c9dcbd",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/c3e2692c7a58e0bdb84bd658d827e89dcecea3ad",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    }
  ],
  "vulnStatus": "Received",
  "descriptions": [
    {
      "lang": "en",
      "value": "In the Linux kernel, the following vulnerability has been resolved:\n\nf2fs: use the mount idmap for the owner check in f2fs_xattr_advise_set()\n\nf2fs_xattr_advise_set() calls inode_owner_or_capable() with &nop_mnt_idmap\nbefore allowing the \"system.advise\" xattr to be set, instead of the idmap\nthat the VFS passes to the ->set() handler.\n\nf2fs supports idmapped mounts, so on such a mount this checks the caller's\nfsuid against the unmapped on-disk owner rather than the mapped owner: the\nactual owner can be wrongly denied with -EPERM and an unrelated caller\nwrongly allowed.  Pass the handler's idmap instead."
    }
  ],
  "lastModified": "2026-09-16T11:16:50.727",
  "sourceIdentifier": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
}