HomeDefectsLIN1023-34783
Fixed

LIN1023-34783 : Security Advisory - linux - CVE-2026-89839

Created: Oct 7, 2026    Updated: Oct 8, 2026
Resolved Date: Oct 7, 2026
Found In Version: 10.23.30.2
Fix Version: 10.23.30.8
Severity: Standard
Applicable for: Wind River Linux LTS 23
Component/s: Kernel

Description

In the Linux kernel, the following vulnerability has been resolved:  f2fs: use the mount idmap for the owner check in f2fs_xattr_advise_set()  f2fs_xattr_advise_set() calls inode_owner_or_capable() with &nop_mnt_idmap before allowing the system.advise xattr to be set, instead of the idmap that the VFS passes to the ->set() handler.  f2fs supports idmapped mounts, so on such a mount this checks the caller's fsuid against the unmapped on-disk owner rather than the mapped owner: the actual owner can be wrongly denied with -EPERM and an unrelated caller wrongly allowed.  Pass the handler's idmap instead.