Impact
The vulnerability stems from the Linux kernel’s nilfs2 filesystem driver trusting the size of super‑root inode metadata before performing bounds checking, resulting in an out‑of‑bounds read – a CWE-788 condition, which is a specific instance of the broader memory safety error CWE-119. If the computed on‑disk footprint of the inode exceeds the size of a filesystem block, the driver will read beyond the end of that block, potentially exposing data that should remain inaccessible. A local attacker who can supply a malformed nilfs2 filesystem image may read arbitrary data from kernel or process memory, leading to information disclosure and possible privilege escalation if the leaked data is subsequently exploited.
Affected Systems
The affected product is the Linux kernel. No specific kernel versions are listed; the issue is present in any kernel build that includes an unpatched nilfs2 implementation prior to the cited commit.
Risk and Exploitability
The CVSS score of 7.1 indicates a medium‑to‑high severity vulnerability. The EPSS score of less than1% suggests that, as of this analysis, the probability of exploitation is low, and the vulnerability has not yet appeared in the CISA Known Exploited Vulnerability catalog. The likely attack vector is local: an attacker must be able to present a crafted filesystem image to the kernel, such as by mounting the filesystem or loading it as part of a privileged operation. While no remote exploitation path is described, the potential impact remains significant should local attackers succeed.
OpenCVE Enrichment
Debian DLA
Debian DSA