Description
In the Linux kernel, the following vulnerability has been resolved:

nilfs2: fix infinite loop in nilfs_clean_segments()

syzbot reported a hung task in nilfs_transaction_begin(). This occurs
because the cleaner ioctl falls into an infinite loop if
nilfs_segctor_construct() repeatedly returns -EROFS (e.g. the device
is remounted as read-only after an I/O error).

Currently in nilfs_clean_segments(), if err is non-zero, it logs the
error and sleeps but doesn't abort when it encounters a terminal error
like -EROFS. This causes the thread to loop forever.

Fix this by breaking out of the loop if nilfs_segctor_construct()
returns -EROFS. This matches the behaviour in
nilfs_segctor_write_out(), which also handles -EROFS.
Published: 2026-09-17
Score: n/a
EPSS: < 1% Very Low
KEV: No
Impact: Denial of Service
Action: Apply patch
AI Analysis

Impact

The kernel's NILFS2 file system contains an infinite loop in the clean_segments routine. When the cleaner ioctl is invoked on a device that has become read‑only after an I/O error, the routine repeatedly calls nilfs_segctor_construct, which returns -EROFS. The current code logs the error and sleeps without breaking out of the loop, causing the kernel thread to block forever. An attacker who can trigger the cleaner ioctl on a vulnerable NILFS2 device can force the kernel to hang, leading to service disruption and potential reboot of the host, while the affected process remains stuck.

Affected Systems

All Linux kernel builds that include the original NILFS2 implementation without the recent patch. Users running NILFS2 file systems on affected kernel versions are at risk, regardless of the specific release, since the patch was applied only in later stable commits and the specific affected version range is not disclosed.

Risk and Exploitability

The EPSS score is below 1%, indicating a very low probability of exploitation in the wild, but the vulnerability still permits denial of service if an attacker can invoke the specific ioctl on a read‑only state. The flaw is not listed in the CISA KEV catalog, suggesting no confirmed exploits yet. Even though the attack surface may be limited to environments that mount NILFS2 and run processes with the rights to issue the ioctl, any such system is vulnerable until the kernel is replaced or patched.

Generated by OpenCVE AI on September 19, 2026 at 13:13 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Update the Linux kernel to a version that includes the nilfs_clean_segments fix or backport the patch to the current kernel.
  • If a kernel upgrade is not immediately possible, unmount or remount any NILFS2 file systems read‑only and avoid or restrict the cleaner ioctl from being invoked on them.
  • Consider disabling NILFS2 support altogether if the filesystem is not required, or migrate critical data to a different filesystem that does not exhibit this flaw.

Generated by OpenCVE AI on September 19, 2026 at 13:13 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Debian DLA Debian DLA DLA-4817-1 linux-6.12 security update
Debian DSA Debian DSA DSA-6528-1 linux security update
History

Sat, 19 Sep 2026 13:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-400

Thu, 17 Sep 2026 16:30:00 +0000

Type Values Removed Values Added
Description In the Linux kernel, the following vulnerability has been resolved: nilfs2: fix infinite loop in nilfs_clean_segments() syzbot reported a hung task in nilfs_transaction_begin(). This occurs because the cleaner ioctl falls into an infinite loop if nilfs_segctor_construct() repeatedly returns -EROFS (e.g. the device is remounted as read-only after an I/O error). Currently in nilfs_clean_segments(), if err is non-zero, it logs the error and sleeps but doesn't abort when it encounters a terminal error like -EROFS. This causes the thread to loop forever. Fix this by breaking out of the loop if nilfs_segctor_construct() returns -EROFS. This matches the behaviour in nilfs_segctor_write_out(), which also handles -EROFS.
Title nilfs2: fix infinite loop in nilfs_clean_segments()
First Time appeared Linux
Linux linux Kernel
CPEs cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
Vendors & Products Linux
Linux linux Kernel
References

Subscriptions

Linux Linux Kernel
cve-icon MITRE

Status: PUBLISHED

Assigner: Linux

Published:

Updated: 2026-09-17T16:09:44.558Z

Reserved: 2026-09-11T19:38:34.813Z

Link: CVE-2026-90420

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-09-17T17:17:46.440

Modified: 2026-09-17T17:17:46.440

Link: CVE-2026-90420

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-19T13:15:16Z

Weaknesses
  • CWE-400

    Uncontrolled Resource Consumption