CVE-2026-93816
In the Linux kernel, the following vulnerability has been resolved:
f2fs: validate inline dentry name lengths before conversion
Inline dentry conversion copies names out of the inline dentry area before checking that each recorded name length fits in the available filename slots.
A corrupted image can therefore make the conversion path read past the inline filename storage while building the regular dentry block.
Validate each inline dentry name length against the inline filename area before copying it.
CVSS
- Versión: 3.1
- Vector: CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:H
- Puntuación base: 7.1
Probabilidad de explotación (EPSS)
- Probabilidad de explotación en los próximos 30 días: 0.13%
- Percentil entre todas las CVEs puntuadas: 2
- Fecha de la puntuación: 5/10/2026
EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).
🎯 Técnicas ATT&CK
Cómo se explota esta vulnerabilidad y qué consigue el atacante, en el lenguaje de MITRE ATT&CK.
- Explotación
T1203Exploitation for Client Executionexecution85 % - Impacto principal
T1005Data from Local Systemcollection75 % - Impacto secundario
T1499.004Application or System Exploitationimpact65 %
Vulnerabilidad de lectura de memoria fuera de límites en conversión de dentry inline del kernel Linux (AV:L, UI:R). Permite leer datos del kernel (C:H) e impacto en disponibilidad (A:H) por DoS.
Inferido por nuestro agente de análisis a partir de la descripción oficial, el vector CVSS y la CWE, y comprobado por un supervisor. Puede contener errores.
🛡️ Mitigaciones ATT&CK que cubren estas técnicas
Tecnologías afectadas (1)
⚠ Inferidas por IA a partir de la descripción — NVD aún no ha analizado esta CVE; no son CPE verificados.
Referencias
- https://git.kernel.org/stable/c/2ce0bc5853bec7cdc724477a87ea579fde664243
- https://git.kernel.org/stable/c/4dd81faa63fd54b9ba1a83c304e6d0bd03f1898d
- https://git.kernel.org/stable/c/6343208fd73f3f2b8044c0922185cd13ff807693
- https://git.kernel.org/stable/c/6b5552449fc5acb8e6ecf045b46702b29b71165a
- https://git.kernel.org/stable/c/7caa8a0ae94b132576c2e46e9b4fd4e0f356f373
- https://git.kernel.org/stable/c/aee4e6de71ca77626c006166ff00f1d01ff990c9
- https://git.kernel.org/stable/c/cfcd0e49a178b3dac2c0ece656079081dbf5da74
JSON original (NVD)
Mostrar
{
"id": "CVE-2026-93816",
"cveTags": [],
"metrics": {
"cvssMetricV31": [
{
"type": "Secondary",
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"cvssData": {
"scope": "UNCHANGED",
"version": "3.1",
"baseScore": 7.1,
"attackVector": "LOCAL",
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:H",
"integrityImpact": "NONE",
"userInteraction": "REQUIRED",
"attackComplexity": "LOW",
"availabilityImpact": "HIGH",
"privilegesRequired": "NONE",
"confidentialityImpact": "HIGH"
},
"impactScore": 5.2,
"exploitabilityScore": 1.8
}
]
},
"affected": [
{
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"affectedData": [
{
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"product": "Linux",
"versions": [
{
"status": "affected",
"version": "675f10bde6cc3874632a8f684df2a8a2a8ace76e",
"lessThan": "6b5552449fc5acb8e6ecf045b46702b29b71165a",
"versionType": "git"
},
{
"status": "affected",
"version": "675f10bde6cc3874632a8f684df2a8a2a8ace76e",
"lessThan": "6343208fd73f3f2b8044c0922185cd13ff807693",
"versionType": "git"
},
{
"status": "affected",
"version": "675f10bde6cc3874632a8f684df2a8a2a8ace76e",
"lessThan": "4dd81faa63fd54b9ba1a83c304e6d0bd03f1898d",
"versionType": "git"
},
{
"status": "affected",
"version": "675f10bde6cc3874632a8f684df2a8a2a8ace76e",
"lessThan": "aee4e6de71ca77626c006166ff00f1d01ff990c9",
"versionType": "git"
},
{
"status": "affected",
"version": "675f10bde6cc3874632a8f684df2a8a2a8ace76e",
"lessThan": "2ce0bc5853bec7cdc724477a87ea579fde664243",
"versionType": "git"
},
{
"status": "affected",
"version": "675f10bde6cc3874632a8f684df2a8a2a8ace76e",
"lessThan": "7caa8a0ae94b132576c2e46e9b4fd4e0f356f373",
"versionType": "git"
},
{
"status": "affected",
"version": "675f10bde6cc3874632a8f684df2a8a2a8ace76e",
"lessThan": "cfcd0e49a178b3dac2c0ece656079081dbf5da74",
"versionType": "git"
}
],
"programFiles": [
"fs/f2fs/inline.c"
],
"defaultStatus": "unaffected"
},
{
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"product": "Linux",
"versions": [
{
"status": "affected",
"version": "4.7"
},
{
"status": "unaffected",
"version": "0",
"lessThan": "4.7",
"versionType": "semver"
},
{
"status": "unaffected",
"version": "5.10.271",
"versionType": "semver",
"lessThanOrEqual": "5.10.*"
},
{
"status": "unaffected",
"version": "5.15.222",
"versionType": "semver",
"lessThanOrEqual": "5.15.*"
},
{
"status": "unaffected",
"version": "6.1.189",
"versionType": "semver",
"lessThanOrEqual": "6.1.*"
},
{
"status": "unaffected",
"version": "6.6.158",
"versionType": "semver",
"lessThanOrEqual": "6.6.*"
},
{
"status": "unaffected",
"version": "6.12.111",
"versionType": "semver",
"lessThanOrEqual": "6.12.*"
},
{
"status": "unaffected",
"version": "6.18.53",
"versionType": "semver",
"lessThanOrEqual": "6.18.*"
},
{
"status": "unaffected",
"version": "7.2",
"versionType": "original_commit_for_fix",
"lessThanOrEqual": "*"
}
],
"programFiles": [
"fs/f2fs/inline.c"
],
"defaultStatus": "affected"
}
]
}
],
"published": "2026-09-24T17:17:15.120",
"references": [
{
"url": "https://git.kernel.org/stable/c/2ce0bc5853bec7cdc724477a87ea579fde664243",
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
},
{
"url": "https://git.kernel.org/stable/c/4dd81faa63fd54b9ba1a83c304e6d0bd03f1898d",
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
},
{
"url": "https://git.kernel.org/stable/c/6343208fd73f3f2b8044c0922185cd13ff807693",
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
},
{
"url": "https://git.kernel.org/stable/c/6b5552449fc5acb8e6ecf045b46702b29b71165a",
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
},
{
"url": "https://git.kernel.org/stable/c/7caa8a0ae94b132576c2e46e9b4fd4e0f356f373",
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
},
{
"url": "https://git.kernel.org/stable/c/aee4e6de71ca77626c006166ff00f1d01ff990c9",
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
},
{
"url": "https://git.kernel.org/stable/c/cfcd0e49a178b3dac2c0ece656079081dbf5da74",
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
}
],
"vulnStatus": "Received",
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\nf2fs: validate inline dentry name lengths before conversion\n\nInline dentry conversion copies names out of the inline dentry area\nbefore checking that each recorded name length fits in the available\nfilename slots.\n\nA corrupted image can therefore make the conversion path read past\nthe inline filename storage while building the regular dentry block.\n\nValidate each inline dentry name length against the inline filename\narea before copying it."
}
],
"lastModified": "2026-10-03T11:17:51.527",
"sourceIdentifier": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
}