Impact
The nilfs2 filesystem contains a defect in the nilfs_copy_dirty_pages() routine. When a dirty page’s flag is cleared asynchronously after the kernel detects metadata corruption and the filesystem switches to read‑only mode, the routine mistakenly attempts to copy the page to a shadow cache. This mismatch triggers a BUG that causes an immediate kernel panic, effectively shutting down the entire system. The patch changes the logic to return an EROFS error if the filesystem is read‑only and to emit a single warning instead of the BUG when the state mismatch occurs while the filesystem is still writable.
Affected Systems
Any Linux kernel that ships with the nilfs2 filesystem compiled in and has not yet incorporated the commit that adds the fix is vulnerable. Because the CVE does not list specific kernel releases, all kernel branches containing the buggy nilfs_copy_dirty_pages() code prior to the patch are affected. Linux distributions using the standard vanilla kernel with nilfs2 support fall into this category.
Risk and Exploitability
Exploitability is considered low, as indicated by an EPSS score below 1% and its absence from CISA’s KEV catalog. The vulnerability requires an attacker to induce metadata corruption on a nilfs2‑mounted filesystem, which in practice would entail local or elevated privileges; this is inferred from the description stating that the flag can be cleared after a corruption check. Successful exploitation would result in a kernel panic and denial of service, but the impact is limited to the affected host and would not provide remote code execution or further privilege escalation. The risk can be fully mitigated by applying the kernel update that implements the described fix.
OpenCVE Enrichment
Debian DLA
Debian DSA