๐Ÿ” CVE Alert

CVE-2026-89723

HIGH 7.8

nilfs2: fix slab-out-of-bounds in nilfs_direct_propagate after truncation

CVSS Score
7.8
EPSS Score
0.0%
EPSS Percentile
0th

In the Linux kernel, the following vulnerability has been resolved: nilfs2: fix slab-out-of-bounds in nilfs_direct_propagate after truncation Shuangpeng Bai reported that KASAN detected a slab-out-of-bounds error in nilfs_direct_propagate() during testing. Analysis revealed that after truncating a file, a node block immediately below the B-tree root was not deleted. Instead, it remained in the B-tree node cache in a dirty state. The log writer subsequently detected this block and incorrectly invoked nilfs_direct_propagate() on it, which is designed to handle only data blocks in direct mapping. B-tree nodes in the cache are managed by virtual block numbers, and their logical keys typically exceed the range expected by direct mapping. Consequently, processing such a node as a direct mapping entry triggers a slab-out-of-bounds access. The root cause is that when a B-tree mapping collapses into a direct mapping during truncation, an intermediate node block pointed to by the root node is left behind as garbage instead of being explicitly deleted. This resolves the issue by adding a nilfs_btree_discard() operation to delete the remaining intermediate node block during the conversion. A 'deform' flag is added to the bop_delete interface to explicitly signal that the deletion is part of a mapping transformation. This allows the B-tree mapping implementation to perform the necessary cleanup and discarding of the residual node structure that would be otherwise be left orphaned after the transition.

Vendor linux
Product linux
Ecosystems
Industries
Technology
Published Sep 11, 2026
Last Updated Sep 14, 2026
Stay Ahead of the Next One

Get instant alerts for linux linux

Be the first to know when new high vulnerabilities affecting linux linux are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

CVSS v3 Breakdown

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Attack Vector
Attack Complexity
Privileges Required
User Interaction
Scope
Confidentiality
Integrity
Availability

Affected Versions

Linux / Linux
36a580eb489f54d81a0534974962e732a314b999 < 39005fd1ce654ffdecacddc406b9a038efe606e6 36a580eb489f54d81a0534974962e732a314b999 < bf49e6f6ddc12445a0330708b365de6458085980 36a580eb489f54d81a0534974962e732a314b999 < 4a1bb1f9f24a935c9b3f4fbf98012fa6d4ad826d 36a580eb489f54d81a0534974962e732a314b999 < b313edfbc0c2a60f7ce09b2e81ee71909ab8ddaf 36a580eb489f54d81a0534974962e732a314b999 < 5d3783c451a546373662ee11ec17019273e68034 36a580eb489f54d81a0534974962e732a314b999 < 448636c745a3f3b8582a0b8ce718c890a11c0fa9 36a580eb489f54d81a0534974962e732a314b999 < 28362e8ce51377afdec1782e661e808328a10514 36a580eb489f54d81a0534974962e732a314b999 < 45662dedb8f272ef7f16e69f13424c4bd0399240
Linux / Linux
2.6.30

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
git.kernel.org: https://git.kernel.org/stable/c/39005fd1ce654ffdecacddc406b9a038efe606e6 git.kernel.org: https://git.kernel.org/stable/c/bf49e6f6ddc12445a0330708b365de6458085980 git.kernel.org: https://git.kernel.org/stable/c/4a1bb1f9f24a935c9b3f4fbf98012fa6d4ad826d git.kernel.org: https://git.kernel.org/stable/c/b313edfbc0c2a60f7ce09b2e81ee71909ab8ddaf git.kernel.org: https://git.kernel.org/stable/c/5d3783c451a546373662ee11ec17019273e68034 git.kernel.org: https://git.kernel.org/stable/c/448636c745a3f3b8582a0b8ce718c890a11c0fa9 git.kernel.org: https://git.kernel.org/stable/c/28362e8ce51377afdec1782e661e808328a10514 git.kernel.org: https://git.kernel.org/stable/c/45662dedb8f272ef7f16e69f13424c4bd0399240