Impact
The vulnerability is a slab‑out‑of‑bounds error in nilfs_direct_propagate that can be triggered after a file is truncated on a nilfs2 filesystem. The bug occurs when a B‑tree mapping collapses into a direct mapping and a background node block is left in the cache as dirty. When the log writer later processes that orphaned node as a direct data block, the function reads outside the allocated slab, corrupting kernel memory. This memory corruption can lead to privilege escalation or a kernel panic. The weakness is identified as CWE‑787 (Out‑of‑bounds Write).
Affected Systems
All systems running a Linux kernel that includes the nilfs2 filesystem and have not yet applied the nilfs_btree_discard fix are affected. The specific kernel versions are not enumerated in the advisory, so any kernel build that predates the commit adding nilfs_btree_discard should be considered vulnerable. Users of distributions that ship the kernel without the patch should check their kernel version or apply the upstream fix.
Risk and Exploitability
The CVSS score of 7.8 indicates high severity. The EPSS score is below 1 %, meaning exploitation is unlikely in the near term, and the vulnerability is not listed in CISA’s KEV catalog. The likely attack vector is local; an attacker must have write or truncate access to a nilfs2 file to trigger the bug. Because the flaw manifests only after a file truncation that leaves an orphaned node in the B-tree cache, it is not trivially exploitable from a remote network alone, but a compromised user or process with sufficient privileges could craft the trigger and cause kernel memory corruption or a crash.
OpenCVE Enrichment
Debian DSA