{"dataType":"CVE_RECORD","dataVersion":"5.2","cveMetadata":{"cveId":"CVE-2026-89723","assignerOrgId":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","state":"PUBLISHED","assignerShortName":"Linux","dateReserved":"2026-09-11T19:38:34.759Z","datePublished":"2026-09-11T19:46:35.161Z","dateUpdated":"2026-09-14T12:02:13.886Z"},"containers":{"cna":{"providerMetadata":{"orgId":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","shortName":"Linux","dateUpdated":"2026-09-14T12:02:13.886Z"},"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nnilfs2: fix slab-out-of-bounds in nilfs_direct_propagate after truncation\n\nShuangpeng Bai reported that KASAN detected a slab-out-of-bounds error\nin nilfs_direct_propagate() during testing.\n\nAnalysis revealed that after truncating a file, a node block immediately\nbelow the B-tree root was not deleted.  Instead, it remained in the B-tree\nnode cache in a dirty state.  The log writer subsequently detected this\nblock and incorrectly invoked nilfs_direct_propagate() on it, which is\ndesigned to handle only data blocks in direct mapping.\n\nB-tree nodes in the cache are managed by virtual block numbers, and their\nlogical keys typically exceed the range expected by direct mapping.\nConsequently, processing such a node as a direct mapping entry triggers\na slab-out-of-bounds access.\n\nThe root cause is that when a B-tree mapping collapses into a direct\nmapping during truncation, an intermediate node block pointed to by the\nroot node is left behind as garbage instead of being explicitly deleted.\n\nThis resolves the issue by adding a nilfs_btree_discard() operation\nto delete the remaining intermediate node block during the conversion.\nA 'deform' flag is added to the bop_delete interface to explicitly signal\nthat the deletion is part of a mapping transformation.  This allows the\nB-tree mapping implementation to perform the necessary cleanup and\ndiscarding of the residual node structure that would be otherwise be left\norphaned after the transition."}],"metrics":[{"cvssV3_1":{"version":"3.1","vectorString":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","baseScore":7.8,"baseSeverity":"HIGH"},"scenarios":[{"lang":"en","value":"AV:L - The defect is reached only through local VFS operations on a mounted nilfs2 volume (write to grow a file into B-tree mapping, ftruncate/setattr to collapse it to direct mapping, then the in-kernel log writer). No network protocol path enters fs/nilfs2/direct.c.\nAC:L - The leftover dirty B-tree node after truncation is a deterministic logic bug, not a race. The attacker controls file layout and size, and can force the segment constructor to process the orphaned node via fsync/sync or the periodic log writer.\nPR:L - Write and truncate go through nilfs_setattr/nilfs_truncate with only ordinary file DAC checks; CAP_SYS_ADMIN in fs/nilfs2/ioctl.c is not on this path. An unprivileged user with write access to an already-mounted nilfs2 volume can trigger it.\nUI:N - On an already-mounted nilfs2 volume the attacker triggers the B-tree-to-direct conversion and the subsequent slab OOB entirely with their own write/ftruncate/fsync; no separate victim action is required.\nS:U - The slab out-of-bounds access corrupts kernel memory within the same kernel security authority; this is local memory corruption/privilege escalation, not a VM, IOMMU, or sandbox boundary crossing.\nC:H - nilfs_direct_propagate indexes the 6-entry direct-pointer array with the leftover B-tree node's virtual block number via nilfs_direct_get_ptr, an unbounded slab out-of-bounds read of adjacent nilfs_inode_info/slab memory that can disclose kernel data.\nI:H - For a non-volatile leftover node, nilfs_direct_set_ptr writes a newly allocated DAT vblock at the same unbounded OOB index, and the OOB-read pointer is passed to nilfs_dat_prepare_update, yielding a kernel write primitive and DAT metadata corruption.\nA:H - The unbounded slab-out-of-bounds access was caught by KASAN and produces a kernel oops/panic when the out-of-range index lands outside mapped slab objects, taking the system down."}]}],"affected":[{"product":"Linux","vendor":"Linux","defaultStatus":"unaffected","repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","programFiles":["fs/nilfs2/bmap.c","fs/nilfs2/bmap.h","fs/nilfs2/btree.c","fs/nilfs2/direct.c"],"versions":[{"version":"36a580eb489f54d81a0534974962e732a314b999","lessThan":"39005fd1ce654ffdecacddc406b9a038efe606e6","status":"affected","versionType":"git"},{"version":"36a580eb489f54d81a0534974962e732a314b999","lessThan":"bf49e6f6ddc12445a0330708b365de6458085980","status":"affected","versionType":"git"},{"version":"36a580eb489f54d81a0534974962e732a314b999","lessThan":"4a1bb1f9f24a935c9b3f4fbf98012fa6d4ad826d","status":"affected","versionType":"git"},{"version":"36a580eb489f54d81a0534974962e732a314b999","lessThan":"b313edfbc0c2a60f7ce09b2e81ee71909ab8ddaf","status":"affected","versionType":"git"},{"version":"36a580eb489f54d81a0534974962e732a314b999","lessThan":"5d3783c451a546373662ee11ec17019273e68034","status":"affected","versionType":"git"},{"version":"36a580eb489f54d81a0534974962e732a314b999","lessThan":"448636c745a3f3b8582a0b8ce718c890a11c0fa9","status":"affected","versionType":"git"},{"version":"36a580eb489f54d81a0534974962e732a314b999","lessThan":"28362e8ce51377afdec1782e661e808328a10514","status":"affected","versionType":"git"},{"version":"36a580eb489f54d81a0534974962e732a314b999","lessThan":"45662dedb8f272ef7f16e69f13424c4bd0399240","status":"affected","versionType":"git"}]},{"product":"Linux","vendor":"Linux","defaultStatus":"affected","repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","programFiles":["fs/nilfs2/bmap.c","fs/nilfs2/bmap.h","fs/nilfs2/btree.c","fs/nilfs2/direct.c"],"versions":[{"version":"2.6.30","status":"affected"},{"version":"0","lessThan":"2.6.30","status":"unaffected","versionType":"semver"},{"version":"5.10.270","lessThanOrEqual":"5.10.*","status":"unaffected","versionType":"semver"},{"version":"5.15.221","lessThanOrEqual":"5.15.*","status":"unaffected","versionType":"semver"},{"version":"6.1.188","lessThanOrEqual":"6.1.*","status":"unaffected","versionType":"semver"},{"version":"6.6.157","lessThanOrEqual":"6.6.*","status":"unaffected","versionType":"semver"},{"version":"6.12.109","lessThanOrEqual":"6.12.*","status":"unaffected","versionType":"semver"},{"version":"6.18.50","lessThanOrEqual":"6.18.*","status":"unaffected","versionType":"semver"},{"version":"7.2.4","lessThanOrEqual":"7.2.*","status":"unaffected","versionType":"semver"},{"version":"7.3-rc1","lessThanOrEqual":"*","status":"unaffected","versionType":"original_commit_for_fix"}]}],"cpeApplicability":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"2.6.30","versionEndExcluding":"5.10.270"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"2.6.30","versionEndExcluding":"5.15.221"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"2.6.30","versionEndExcluding":"6.1.188"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"2.6.30","versionEndExcluding":"6.6.157"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"2.6.30","versionEndExcluding":"6.12.109"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"2.6.30","versionEndExcluding":"6.18.50"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"2.6.30","versionEndExcluding":"7.2.4"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"2.6.30","versionEndExcluding":"7.3-rc1"}]}]}],"references":[{"url":"https://git.kernel.org/stable/c/39005fd1ce654ffdecacddc406b9a038efe606e6"},{"url":"https://git.kernel.org/stable/c/bf49e6f6ddc12445a0330708b365de6458085980"},{"url":"https://git.kernel.org/stable/c/4a1bb1f9f24a935c9b3f4fbf98012fa6d4ad826d"},{"url":"https://git.kernel.org/stable/c/b313edfbc0c2a60f7ce09b2e81ee71909ab8ddaf"},{"url":"https://git.kernel.org/stable/c/5d3783c451a546373662ee11ec17019273e68034"},{"url":"https://git.kernel.org/stable/c/448636c745a3f3b8582a0b8ce718c890a11c0fa9"},{"url":"https://git.kernel.org/stable/c/28362e8ce51377afdec1782e661e808328a10514"},{"url":"https://git.kernel.org/stable/c/45662dedb8f272ef7f16e69f13424c4bd0399240"}],"title":"nilfs2: fix slab-out-of-bounds in nilfs_direct_propagate after truncation","x_generator":{"engine":"bippy-1.2.0"}}}}