Status: UPDATED | Advisory ID: CVE-2026-93816
| CVE | CVE-2026-93816 |
| CVSS Score / Version | 7.1 (High) / CVSS v3.1 |
| Updated | 2026-09-25 |
| CVSS Vector | CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:H |
| CVSS Prose | attack vector is local; attack complexity is low; privileges required is none; user interaction is required; scope is unchanged; confidentiality impact is high; integrity impact is none; availability impact is high. |
| Affected products | Linux Linux |
| Vendor | Product | Affected Versions | Patch Status |
|---|---|---|---|
| Linux | Linux |
| Subsystems | General OT |
| Sectors | Multiple |
In the Linux kernel, the following vulnerability has been resolved:
f2fs: validate inline dentry name lengths before conversion
Inline dentry conversion copies names out of the inline dentry area
before checking that each recorded name length fits in the available
filename slots.
A corrupted image can therefore make the conversion path read past
the inline filename storage while building the regular dentry block.
Validate each inline dentry name length against the inline filename
area before copying it. (NVD)
Monitor Linux's web page for any future patch releases.
| Source | Reference |
|---|---|
| NVD | https://nvd.nist.gov/vuln/detail/CVE-2026-93816 |
| CVE | https://www.cve.org/CVERecord?id=CVE-2026-93816 |