Impact
The kernel's NILFS2 file system contains an infinite loop in the clean_segments routine. When the cleaner ioctl is invoked on a device that has become read‑only after an I/O error, the routine repeatedly calls nilfs_segctor_construct, which returns -EROFS. The current code logs the error and sleeps without breaking out of the loop, causing the kernel thread to block forever. An attacker who can trigger the cleaner ioctl on a vulnerable NILFS2 device can force the kernel to hang, leading to service disruption and potential reboot of the host, while the affected process remains stuck.
Affected Systems
All Linux kernel builds that include the original NILFS2 implementation without the recent patch. Users running NILFS2 file systems on affected kernel versions are at risk, regardless of the specific release, since the patch was applied only in later stable commits and the specific affected version range is not disclosed.
Risk and Exploitability
The EPSS score is below 1%, indicating a very low probability of exploitation in the wild, but the vulnerability still permits denial of service if an attacker can invoke the specific ioctl on a read‑only state. The flaw is not listed in the CISA KEV catalog, suggesting no confirmed exploits yet. Even though the attack surface may be limited to environments that mount NILFS2 and run processes with the rights to issue the ioctl, any such system is vulnerable until the kernel is replaced or patched.
OpenCVE Enrichment
Debian DLA
Debian DSA