OCTOBER 9, 2026
Live Feed
Back to database
Case File

CVE-2026-93816

HIGH · CVSS 7.1 EPSS 0.13%

Source: NVD + CISA KEV + EPSS · Published 2026-09-24 · Last synced 2026-10-09

CyberRota Analysis

AI-Generated

The vulnerability affects the Linux kernel's f2fs filesystem, specifically during the conversion of inline directory entries (dentries) where it fails to validate the lengths of names before copying them. This oversight can lead to potential out-of-bounds reads, which may compromise system integrity or lead to crashes when processing corrupted images. System administrators and developers working with Linux-based environments, particularly those utilizing f2fs, should prioritize applying the relevant patches to mitigate this risk.

CVE
CVE-2026-93816
Severity
HIGH
CVSS
7.1
EPSS
0.13%
Linux

Original NVD Description

In the Linux kernel, the following vulnerability has been resolved: f2fs: validate inline dentry name lengths before conversion Inline dentry conversion copies names out of the inline dentry area before checking that each recorded name length fits in the available filename slots. A corrupted image can therefore make the conversion path read past the inline filename storage while building the regular dentry block. Validate each inline dentry name length against the inline filename area before copying it.