Description
In the Linux kernel, the following vulnerability has been resolved:

nilfs2: prevent out-of-bounds read in super root block parsing

super-root inode metadata size is trusted before nilfs_read_inode_common().

Reject super-root inode sizes whose computed on-disk footprint exceeds the
filesystem block size. This prevents malformed filesystem images from
making nilfs_read_inode_common() read past the end of the super-root block.

[ryusuke: clarify the commit title]
Published: 2026-09-17
Score: 7.1 High
EPSS: < 1% Very Low
KEV: No
Impact: Information disclosure
Action: Apply patch
AI Analysis

Impact

The vulnerability stems from the Linux kernel’s nilfs2 filesystem driver trusting the size of super‑root inode metadata before performing bounds checking, resulting in an out‑of‑bounds read – a CWE-788 condition, which is a specific instance of the broader memory safety error CWE-119. If the computed on‑disk footprint of the inode exceeds the size of a filesystem block, the driver will read beyond the end of that block, potentially exposing data that should remain inaccessible. A local attacker who can supply a malformed nilfs2 filesystem image may read arbitrary data from kernel or process memory, leading to information disclosure and possible privilege escalation if the leaked data is subsequently exploited.

Affected Systems

The affected product is the Linux kernel. No specific kernel versions are listed; the issue is present in any kernel build that includes an unpatched nilfs2 implementation prior to the cited commit.

Risk and Exploitability

The CVSS score of 7.1 indicates a medium‑to‑high severity vulnerability. The EPSS score of less than1% suggests that, as of this analysis, the probability of exploitation is low, and the vulnerability has not yet appeared in the CISA Known Exploited Vulnerability catalog. The likely attack vector is local: an attacker must be able to present a crafted filesystem image to the kernel, such as by mounting the filesystem or loading it as part of a privileged operation. While no remote exploitation path is described, the potential impact remains significant should local attackers succeed.

Generated by OpenCVE AI on September 20, 2026 at 01:17 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Deploy a kernel version that includes the nilfs2 patch that enforces bounds checking on super‑root inode sizes.
  • Restrict any privileged or untrusted users from mounting nilfs2 filesystems or from providing arbitrary filesystem images to the kernel.
  • Recompile the kernel or remove the nilfs2 module if nilfs2 support is not required.

Generated by OpenCVE AI on September 20, 2026 at 01:17 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Debian DLA Debian DLA DLA-4817-1 linux-6.12 security update
Debian DSA Debian DSA DSA-6528-1 linux security update
History

Sun, 20 Sep 2026 01:45:00 +0000

Type Values Removed Values Added
Weaknesses CWE-119
CWE-788

Sat, 19 Sep 2026 23:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-119
CWE-788

Sat, 19 Sep 2026 14:00:00 +0000

Type Values Removed Values Added
Weaknesses CWE-119
CWE-788

Fri, 18 Sep 2026 21:30:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 7.1, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:H'}


Thu, 17 Sep 2026 16:30:00 +0000

Type Values Removed Values Added
Description In the Linux kernel, the following vulnerability has been resolved: nilfs2: prevent out-of-bounds read in super root block parsing super-root inode metadata size is trusted before nilfs_read_inode_common(). Reject super-root inode sizes whose computed on-disk footprint exceeds the filesystem block size. This prevents malformed filesystem images from making nilfs_read_inode_common() read past the end of the super-root block. [ryusuke: clarify the commit title]
Title nilfs2: prevent out-of-bounds read in super root block parsing
First Time appeared Linux
Linux linux Kernel
CPEs cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
Vendors & Products Linux
Linux linux Kernel
References

Subscriptions

Linux Linux Kernel
cve-icon MITRE

Status: PUBLISHED

Assigner: Linux

Published:

Updated: 2026-09-18T17:55:17.275Z

Reserved: 2026-09-11T19:38:34.813Z

Link: CVE-2026-90419

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-09-17T17:17:46.290

Modified: 2026-09-18T18:17:58.473

Link: CVE-2026-90419

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-20T01:30:16Z

Weaknesses
  • CWE-119

    Improper Restriction of Operations within the Bounds of a Memory Buffer

  • CWE-788

    Access of Memory Location After End of Buffer