CVE-2026-23267Linux vulnerability

9 documents8 sources
Severity
7.1HIGH
No vector
EPSS
0.0%
top 90.88%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedMar 18

Description

In the Linux kernel, the following vulnerability has been resolved: f2fs: fix IS_CHECKPOINTED flag inconsistency issue caused by concurrent atomic commit and checkpoint writes During SPO tests, when mounting F2FS, an -EINVAL error was returned from f2fs_recover_inode_page. The issue occurred under the following scenario Thread A Thread B f2fs_ioc_commit_atomic_write - f2fs_do_sync_file // atomic = true - f2fs_fsync_node_pages : last_folio = inode folio : schedule before folio_lock(last_folio)

Affected Packages3 packages

Linuxlinux/linux_kernel4.7.06.1.164+4
Debianlinux/linux_kernel< 6.1.164-1+2
CVEListV5linux/linux608514deba38c8611ad330d6a3c8e2b9a1f68e4b32bc3c9fe18881d50dd51fd5f26d19fe1190dc0d+6

🔴Vulnerability Details

4
OSV
CVE-2026-23267: In the Linux kernel, the following vulnerability has been resolved: f2fs: fix IS_CHECKPOINTED flag inconsistency issue caused by concurrent atomic com2026-03-18
GHSA
GHSA-9m9w-6gjg-9m6r: In the Linux kernel, the following vulnerability has been resolved: f2fs: fix IS_CHECKPOINTED flag inconsistency issue caused by concurrent atomic co2026-03-18
OSV
f2fs: fix IS_CHECKPOINTED flag inconsistency issue caused by concurrent atomic commit and checkpoint writes2026-03-18
CVEList
f2fs: fix IS_CHECKPOINTED flag inconsistency issue caused by concurrent atomic commit and checkpoint writes2026-03-18

📋Vendor Advisories

3
Red Hat
kernel: f2fs: fix IS_CHECKPOINTED flag inconsistency issue caused by concurrent atomic commit and checkpoint writes2026-03-18
Microsoft
f2fs: fix IS_CHECKPOINTED flag inconsistency issue caused by concurrent atomic commit and checkpoint writes2026-03-10
Debian
CVE-2026-23267: linux - In the Linux kernel, the following vulnerability has been resolved: f2fs: fix I...2026

🕵️Threat Intelligence

1
Wiz
CVE-2026-23267 Impact, Exploitability, and Mitigation Steps | Wiz
CVE-2026-23267 — Linux vulnerability | cvebase