In the Linux kernel, the following vulnerability has been...
High severity
Unreviewed
Published
Aug 19, 2025
to the GitHub Advisory Database
•
Updated Jan 9, 2026
Description
Published by the National Vulnerability Database
Aug 19, 2025
Published to the GitHub Advisory Database
Aug 19, 2025
Last updated
Jan 9, 2026
In the Linux kernel, the following vulnerability has been resolved:
f2fs: fix KMSAN uninit-value in extent_info usage
KMSAN reported a use of uninitialized value in
__is_extent_mergeable()and
__is_back_mergeable()via the read extent tree path.The root cause is that
get_read_extent_info()only initializes threefields (
fofs,blk,len) ofstruct extent_info, leaving theremaining fields uninitialized. This leads to undefined behavior
when those fields are accessed later, especially during
extent merging.
Fix it by zero-initializing the
extent_infostruct before population.References