f2fs_fill_dentries of the file fs/f2fs/dir.c of the component F2fs. Performing a manipulation of the argument i_inline_xattr_size results in out-of-bounds read.
This vulnerability is identified as CVE-2026-63815. The attack can be initiated remotely. There is not any exploit available.
Upgrading the affected component is recommended.
Intelligence View
⚡ tsecurity.de Intelligence
CVE-2026-63815 | Linux Kernel up to 6.12.95/6.18.38/7.1.2 F2fs fs/f2fs/dir.c f2fs_fill_dentries i_inline_xattr_size out-of-bounds (WID-SEC-2026-2403)
A vulnerability was found in Linux Kernel up to 6.12.95/6.18.38/7.1.2. It has been classified as critical. Affected is the function
SOCIAL SHARE CARD GENERATOR