CVE-2026-23233

Source
https://cve.org/CVERecord?id=CVE-2026-23233
Import Source
https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2026-23233.json
JSON Data
https://api.test.osv.dev/v1/vulns/CVE-2026-23233
Downstream
Published
2026-03-04T14:36:38.076Z
Modified
2026-03-09T23:55:13.422974Z
Summary
f2fs: fix to avoid mapping wrong physical block for swapfile
Details

In the Linux kernel, the following vulnerability has been resolved:

f2fs: fix to avoid mapping wrong physical block for swapfile

Xiaolong Guo reported a f2fs bug in bugzilla [1]

[1] https://bugzilla.kernel.org/show_bug.cgi?id=220951

Quoted:

"When using stress-ng's swap stress test on F2FS filesystem with kernel 6.6+, the system experiences data corruption leading to either: 1 dm-verity corruption errors and device reboot 2 F2FS node corruption errors and boot hangs

The issue occurs specifically when: 1 Using F2FS filesystem (ext4 is unaffected) 2 Swapfile size is less than F2FS section size (2MB) 3 Swapfile has fragmented physical layout (multiple non-contiguous extents) 4 Kernel version is 6.6+ (6.1 is unaffected)

The root cause is in checkswapactivate() function in fs/f2fs/data.c. When the first extent of a small swapfile (< 2MB) is not aligned to section boundaries, the function incorrectly treats it as the last extent, failing to map subsequent extents. This results in incorrect swap_extent creation where only the first extent is mapped, causing subsequent swap writes to overwrite wrong physical locations (other files' data).

Steps to Reproduce 1 Setup a device with F2FS-formatted userdata partition 2 Compile stress-ng from https://github.com/ColinIanKing/stress-ng 3 Run swap stress test: (Android devices) adb shell "cd /data/stressng; ./stress-ng-64 --metrics-brief --timeout 60 --swap 0"

Log: 1 Ftrace shows in kernel 6.6, only first extent is mapped during second f2fsmapblocks call in checkswapactivate(): stress-ng-swap-8990: f2fsmapblocks: ino=11002, file offset=0, start blkaddr=0x43143, len=0x1 (Only 4KB mapped, not the full swapfile) 2 in kernel 6.1, both extents are correctly mapped: stress-ng-swap-5966: f2fsmapblocks: ino=28011, file offset=0, start blkaddr=0x13cd4, len=0x1 stress-ng-swap-5966: f2fsmapblocks: ino=28011, file offset=1, start blkaddr=0x60c84b, len=0xff

The problematic code is in checkswapactivate(): if ((pblock - SMI(sbi)->mainblkaddr) % blkspersec || nrpblocks % blkspersec || !f2fsvalidpinnedarea(sbi, pblock)) { bool last_extent = false;

not_aligned++;

nr_pblocks = roundup(nr_pblocks, blks_per_sec);
if (cur_lblock + nr_pblocks > sis->max)
    nr_pblocks -= blks_per_sec;

/* this extent is last one */
if (!nr_pblocks) {
    nr_pblocks = last_lblock - cur_lblock;
    last_extent = true;
}

ret = f2fs_migrate_blocks(inode, cur_lblock, nr_pblocks);
if (ret) {
    if (ret == -ENOENT)
        ret = -EINVAL;
    goto out;
}

if (!last_extent)
    goto retry;

}

When the first extent is unaligned and roundup(nrpblocks, blkspersec) exceeds sis->max, we subtract blkspersec resulting in nrpblocks = 0. The code then incorrectly assumes this is the last extent, sets nrpblocks = lastlblock - cur_lblock (entire swapfile), and performs migration. After migration, it doesn't retry mapping, so subsequent extents are never processed. "

In order to fix this issue, we need to lookup block mapping info after we migrate all blocks in the tail of swapfile.

Database specific
{
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/23xxx/CVE-2026-23233.json",
    "cna_assigner": "Linux"
}
References

Affected packages

Git / git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git

Affected ranges

Type
GIT
Repo
https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git
Events
Introduced
40d76c393cca83938b11eb7ca8983aa3cd0ed69b
Fixed
d4534a7f6c92baaf7e12a45fc6e37332cafafc33
Type
GIT
Repo
https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git
Events
Introduced
9703d69d9d153bb230711d0d577454552aeb13d4
Fixed
1ff415eef513bf12deb058fc50d57788c46c48e6
Fixed
fee27b69dde1a05908b350eea42937af2387c4fe
Fixed
607cb9d83838d2cd9f0406c2403ed61aadf0edff
Fixed
5c145c03188bc9ba1c29e0bc4d527a5978fc47f9

Database specific

source
"https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2026-23233.json"

Linux / Kernel

Package

Name
Kernel

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
6.6.127
Type
ECOSYSTEM
Events
Introduced
6.7.0
Fixed
6.12.74
Type
ECOSYSTEM
Events
Introduced
6.9.0
Fixed
6.18.13
Type
ECOSYSTEM
Events
Introduced
6.13.0
Fixed
6.19.3

Database specific

source
"https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2026-23233.json"