CVE-2026-80591: Linux
High severity, CVSS 7.8. EPSS: 0.2% chance of exploitation in the next 30 days.
In the Linux kernel, the following vulnerability has been resolved: f2fs: fix listxattr handling of corrupted xattr entries Validate the xattr entry before reading its fields in f2fs_listxattr(). Return -EFSCORRUPTED when the entry is outside the valid xattr storage area instead of returning a successful partial result.
Affected products
- Linux Linux: from 4.14.181, before 4.15 (fixed in 4.15); from 4.19.119, before 4.20 (fixed in 4.20); from 5.4.36, before 5.5 (fixed in 5.5); from 5.5, before 5.10.261 (fixed in 5.10.261); from 5.11, before 5.15.212 (fixed in 5.15.212); from 5.16, before 6.1.178 (fixed in 6.1.178); …
Published 2026-08-28. Last modified 2026-08-29.