CVE-2017-18249: Debian Linux

High severity, CVSS 7.0. EPSS: 0.3% chance of exploitation in the next 30 days.

The add_free_nid function in fs/f2fs/node.c in the Linux kernel before 4.12 does not properly track an allocated nid, which allows local users to cause a denial of service (race condition) or possibly have unspecified other impact via concurrent threads.

Affected products

  • Debian Debian Linux: version 8.0 only
  • Linux Linux Kernel: before 4.12 (fixed in 4.12)

Published 2018-03-26. Last modified 2026-06-17.