{"dataType":"CVE_RECORD","dataVersion":"5.2","cveMetadata":{"cveId":"CVE-2026-80807","assignerOrgId":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","state":"PUBLISHED","assignerShortName":"Linux","dateReserved":"2026-08-26T14:34:25.794Z","datePublished":"2026-09-04T15:13:23.605Z","dateUpdated":"2026-09-04T15:13:23.605Z"},"containers":{"cna":{"providerMetadata":{"orgId":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","shortName":"Linux","dateUpdated":"2026-09-04T15:13:23.605Z"},"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nnilfs2: reject invalid block index in GC ioctl\n\nSyzbot reported list corruption caused by a double list_add_tail() call on\nbh->b_assoc_buffers within nilfs_lookup_dirty_data_buffers().\n\nAnalysis revealed that the root cause was the insertion of a page/folio\nwith a page index of ULONG_MAX into the page cache via the GC ioctl.\nfilemap_get_folios_tag(), called by nilfs_lookup_dirty_data_buffers(),\nrepeatedly detects a dirty folio with a page index of ULONG_MAX due to\nindex wrap-around, leading to duplicate processing of dirty buffers.\n\nAs a preparatory step, the GC ioctl loads the page/folio of the block to\nbe moved during GC and inserts it into the page cache based on information\nin the nilfs_vdesc structure passed as an argument.  Normally, this does\nnot cause issues because the user-space GC library configures the\nnilfs_vdesc structure properly.  However, since there is no range check on\nthe parameters determining the page index, a request with artificially\ncrafted parameters -- such as those generated by Syzbot -- can result in a\npage/folio being inserted with a page index of ULONG_MAX, triggering the\nabove problem.\n\nThis resolves the issue by checking the ranges of 'vd_offset' and\n'vd_vblocknr' in the nilfs_vdesc structure that determine the page index,\nthereby preventing the invalid page/folio insertions."}],"affected":[{"product":"Linux","vendor":"Linux","defaultStatus":"unaffected","repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","programFiles":["fs/nilfs2/ioctl.c"],"versions":[{"version":"7942b919f7321f95a777d396ff7894a7a83dc9b0","lessThan":"898404cdf882d7b54f1132f75570984ca3214796","status":"affected","versionType":"git"},{"version":"7942b919f7321f95a777d396ff7894a7a83dc9b0","lessThan":"ba8a8b563a28d358c45c62a306d421434a058648","status":"affected","versionType":"git"},{"version":"7942b919f7321f95a777d396ff7894a7a83dc9b0","lessThan":"3bd064ccc70b85f9a3d53aece29dc8473be5a226","status":"affected","versionType":"git"},{"version":"7942b919f7321f95a777d396ff7894a7a83dc9b0","lessThan":"a5e776e2937581d67ec5b9b4d27b0f70d7baa6b1","status":"affected","versionType":"git"},{"version":"7942b919f7321f95a777d396ff7894a7a83dc9b0","lessThan":"68aa9ab6f8f2895713aa6ddf781463ed8ea5ba44","status":"affected","versionType":"git"},{"version":"7942b919f7321f95a777d396ff7894a7a83dc9b0","lessThan":"e447f7edb99bd00cec63d6f3049e2e5074946f71","status":"affected","versionType":"git"},{"version":"7942b919f7321f95a777d396ff7894a7a83dc9b0","lessThan":"ec6ddf271dfa4c7e3147bc2c8b2bad4315f316a1","status":"affected","versionType":"git"},{"version":"7942b919f7321f95a777d396ff7894a7a83dc9b0","lessThan":"fbcfb75c20d71a5b542ad4ac3b79d10b997c8152","status":"affected","versionType":"git"},{"version":"7942b919f7321f95a777d396ff7894a7a83dc9b0","lessThan":"a1735eae55448bc79c2da6593455791e886f6ed8","status":"affected","versionType":"git"}]},{"product":"Linux","vendor":"Linux","defaultStatus":"affected","repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","programFiles":["fs/nilfs2/ioctl.c"],"versions":[{"version":"2.6.30","status":"affected"},{"version":"0","lessThan":"2.6.30","status":"unaffected","versionType":"semver"},{"version":"5.10.269","lessThanOrEqual":"5.10.*","status":"unaffected","versionType":"semver"},{"version":"5.15.220","lessThanOrEqual":"5.15.*","status":"unaffected","versionType":"semver"},{"version":"6.1.187","lessThanOrEqual":"6.1.*","status":"unaffected","versionType":"semver"},{"version":"6.6.156","lessThanOrEqual":"6.6.*","status":"unaffected","versionType":"semver"},{"version":"6.12.108","lessThanOrEqual":"6.12.*","status":"unaffected","versionType":"semver"},{"version":"6.18.47","lessThanOrEqual":"6.18.*","status":"unaffected","versionType":"semver"},{"version":"7.1.11","lessThanOrEqual":"7.1.*","status":"unaffected","versionType":"semver"},{"version":"7.2.1","lessThanOrEqual":"7.2.*","status":"unaffected","versionType":"semver"},{"version":"7.3-rc1","lessThanOrEqual":"*","status":"unaffected","versionType":"original_commit_for_fix"}]}],"cpeApplicability":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"2.6.30","versionEndExcluding":"5.10.269"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"2.6.30","versionEndExcluding":"5.15.220"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"2.6.30","versionEndExcluding":"6.1.187"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"2.6.30","versionEndExcluding":"6.6.156"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"2.6.30","versionEndExcluding":"6.12.108"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"2.6.30","versionEndExcluding":"6.18.47"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"2.6.30","versionEndExcluding":"7.1.11"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"2.6.30","versionEndExcluding":"7.2.1"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"2.6.30","versionEndExcluding":"7.3-rc1"}]}]}],"references":[{"url":"https://git.kernel.org/stable/c/898404cdf882d7b54f1132f75570984ca3214796"},{"url":"https://git.kernel.org/stable/c/ba8a8b563a28d358c45c62a306d421434a058648"},{"url":"https://git.kernel.org/stable/c/3bd064ccc70b85f9a3d53aece29dc8473be5a226"},{"url":"https://git.kernel.org/stable/c/a5e776e2937581d67ec5b9b4d27b0f70d7baa6b1"},{"url":"https://git.kernel.org/stable/c/68aa9ab6f8f2895713aa6ddf781463ed8ea5ba44"},{"url":"https://git.kernel.org/stable/c/e447f7edb99bd00cec63d6f3049e2e5074946f71"},{"url":"https://git.kernel.org/stable/c/ec6ddf271dfa4c7e3147bc2c8b2bad4315f316a1"},{"url":"https://git.kernel.org/stable/c/fbcfb75c20d71a5b542ad4ac3b79d10b997c8152"},{"url":"https://git.kernel.org/stable/c/a1735eae55448bc79c2da6593455791e886f6ed8"}],"title":"nilfs2: reject invalid block index in GC ioctl","x_generator":{"engine":"bippy-1.2.0"}}}}