Description
In the Linux kernel, the following vulnerability has been resolved:

nilfs2: fix BUG in nilfs_copy_dirty_pages() on dirty state mismatch

Syzbot reported a kernel BUG triggered within nilfs_copy_dirty_pages(),
which copies dirty DAT file folios/pages to its shadow page cache. The
BUG occurs when a retrieved dirty folio/page unexpectedly loses its
'dirty' status.

This issue arises because, since the commit referenced below, the 'dirty'
flag of a folio/page can be cleared asynchronously after the filesystem
detects metadata corruption and transitions to read-only mode.

Resolve the issue by returning an -EROFS error if the filesystem has
transitioned to read-only mode. Also change the behavior to issue a
kernel warning only once instead of triggering a kernel BUG when this
unexpected 'dirty' state is detected while the filesystem is not in
read-only mode.
Published: 2026-09-17
Score: n/a
EPSS: < 1% Very Low
KEV: No
Impact: Denial of Service via kernel crash
Action: Apply Patch
AI Analysis

Impact

The nilfs2 filesystem contains a defect in the nilfs_copy_dirty_pages() routine. When a dirty page’s flag is cleared asynchronously after the kernel detects metadata corruption and the filesystem switches to read‑only mode, the routine mistakenly attempts to copy the page to a shadow cache. This mismatch triggers a BUG that causes an immediate kernel panic, effectively shutting down the entire system. The patch changes the logic to return an EROFS error if the filesystem is read‑only and to emit a single warning instead of the BUG when the state mismatch occurs while the filesystem is still writable.

Affected Systems

Any Linux kernel that ships with the nilfs2 filesystem compiled in and has not yet incorporated the commit that adds the fix is vulnerable. Because the CVE does not list specific kernel releases, all kernel branches containing the buggy nilfs_copy_dirty_pages() code prior to the patch are affected. Linux distributions using the standard vanilla kernel with nilfs2 support fall into this category.

Risk and Exploitability

Exploitability is considered low, as indicated by an EPSS score below 1% and its absence from CISA’s KEV catalog. The vulnerability requires an attacker to induce metadata corruption on a nilfs2‑mounted filesystem, which in practice would entail local or elevated privileges; this is inferred from the description stating that the flag can be cleared after a corruption check. Successful exploitation would result in a kernel panic and denial of service, but the impact is limited to the affected host and would not provide remote code execution or further privilege escalation. The risk can be fully mitigated by applying the kernel update that implements the described fix.

Generated by OpenCVE AI on September 19, 2026 at 14:55 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade the Linux kernel to a version that includes the nilfs2 bug fix, which changes the handling to return –EROFS and issue only a single warning instead of triggering a BUG.
  • Check your distribution’s kernel changelog or vendor release notes for the commit that adds the nilfs2 fix and apply the update as soon as it becomes available.
  • Monitor kernel logs (dmesg, syslog) for BUG or panic messages associated with nilfs2; if a crash occurs on an unpatched system, upgrade the kernel immediately.

Generated by OpenCVE AI on September 19, 2026 at 14:55 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Debian DLA Debian DLA DLA-4817-1 linux-6.12 security update
Debian DSA Debian DSA DSA-6528-1 linux security update
History

Thu, 17 Sep 2026 16:30:00 +0000

Type Values Removed Values Added
Description In the Linux kernel, the following vulnerability has been resolved: nilfs2: fix BUG in nilfs_copy_dirty_pages() on dirty state mismatch Syzbot reported a kernel BUG triggered within nilfs_copy_dirty_pages(), which copies dirty DAT file folios/pages to its shadow page cache. The BUG occurs when a retrieved dirty folio/page unexpectedly loses its 'dirty' status. This issue arises because, since the commit referenced below, the 'dirty' flag of a folio/page can be cleared asynchronously after the filesystem detects metadata corruption and transitions to read-only mode. Resolve the issue by returning an -EROFS error if the filesystem has transitioned to read-only mode. Also change the behavior to issue a kernel warning only once instead of triggering a kernel BUG when this unexpected 'dirty' state is detected while the filesystem is not in read-only mode.
Title nilfs2: fix BUG in nilfs_copy_dirty_pages() on dirty state mismatch
First Time appeared Linux
Linux linux Kernel
CPEs cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
Vendors & Products Linux
Linux linux Kernel
References

Subscriptions

Linux Linux Kernel
cve-icon MITRE

Status: PUBLISHED

Assigner: Linux

Published:

Updated: 2026-09-17T16:09:43.223Z

Reserved: 2026-09-11T19:38:34.813Z

Link: CVE-2026-90418

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-09-17T17:17:46.167

Modified: 2026-09-17T17:17:46.167

Link: CVE-2026-90418

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-19T15:00:12Z

Weaknesses

No weakness.