{"id":"CVE-2026-89840","published":"2026-09-16T11:16:50.837","lastModified":"2026-09-21T14:17:27.507","description":"In the Linux kernel, the following vulnerability has been resolved:\n\nf2fs: validate MOVE_RANGE destination size\n\nF2FS_IOC_MOVE_RANGE checks the source range, but not the destination end\nbefore updating i_size. A source hole can expose this: __clone_blkaddrs()\nskips NULL_ADDR entries and returns success, so the caller can still extend\nthe destination inode with unchecked pos_out + len.\n\nReject destination overflow and use inode_newsize_ok() before extending\nthe destination inode.","cvssScore":7.1,"cvssSeverity":"HIGH","cvssVector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H","cwes":[],"vendors":[],"products":[],"references":[{"url":"https://git.kernel.org/stable/c/db13064669526494cd78ba3a4394063b740e940c","tags":[]},{"url":"https://git.kernel.org/stable/c/dcae1eeda53149f219dd6af93b3083b7271c1c63","tags":[]},{"url":"https://git.kernel.org/stable/c/e533889fc26aea0cd83c90327063f272061dd820","tags":[]}],"exploitRefs":[],"hasPoc":false,"ai":null}