CVE-2026-80591
HIGH 7.8In the Linux kernel, the following vulnerability has been resolved: f2fs: fix listxattr handling of corrupted xattr entries Validate the xattr entry before reading its fields in f2fs_listxattr(). Return -EFSCORRUPTED when the entry is outside the valid xattr storage area instead of returning a successful partial result.
Severe if exploited (CVSS 7.8), but no known exploitation and low modeled probability. Patch on a normal cadence.
Exploitation likelihood
0.2%chance of exploitation in 30 days · 7th percentile
Impact if exploited
7.8CVSS 3.1 · HIGH
- ConfidentialityHigh
- IntegrityHigh
- AvailabilityHigh
What an attacker needs
- ⚠Access: Requires local access to the host
- ⚠Privileges: Requires a low-privilege account
- ✓User interaction: No user interaction needed
- ✓Complexity: No special conditions — reliably repeatable
✓ lowers the bar for an attacker · ⚠ raises it
Proof of concept & exploit code
- github-search Search GitHub for public PoC repos
Test against your own equipment
curl -s https://vulnpedia.com/cve/CVE-2026-80591/poc.jsonMachine-readable PoC index for this CVE (for automation).Listed for defensive triage, patch verification, and authorized testing on systems you own. Machine-readable: /cve/CVE-2026-80591/poc.json
Weakness (CWE)
Not classified.
CVSS vector
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
References
Technical & other
- https://git.kernel.org/stable/c/7dfac47e4189692f35230f3064acf2540e6d75fe
- https://git.kernel.org/stable/c/c8a10f174316e80d577e6549099b71a7a2111f3f
- https://git.kernel.org/stable/c/dfa4891c27bccbd83d511a065721e85621f275a1
- https://git.kernel.org/stable/c/2770041f34b52334ea63351ffb1cc2007a9de46e
- https://git.kernel.org/stable/c/7dd01f7d0291583e3e5420c95c7d584e114899bd
- https://git.kernel.org/stable/c/ec9f79c8d5b28a928e65b67cd138c841571cf502
- https://git.kernel.org/stable/c/3c0dbfecd859fd02fe9008f33a83146102ccd9ba
- https://git.kernel.org/stable/c/5ef5bc304f23c3fe255d4936472378dcb74d0e94