{"dataType":"CVE_RECORD","dataVersion":"5.2","cveMetadata":{"cveId":"CVE-2026-90419","assignerOrgId":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","state":"PUBLISHED","assignerShortName":"Linux","dateReserved":"2026-09-11T19:38:34.813Z","datePublished":"2026-09-17T16:09:43.880Z","dateUpdated":"2026-09-18T17:55:17.275Z"},"containers":{"cna":{"providerMetadata":{"orgId":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","shortName":"Linux","dateUpdated":"2026-09-18T17:55:17.275Z"},"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nnilfs2: prevent out-of-bounds read in super root block parsing\n\nsuper-root inode metadata size is trusted before nilfs_read_inode_common().\n\nReject super-root inode sizes whose computed on-disk footprint exceeds the\nfilesystem block size. This prevents malformed filesystem images from\nmaking nilfs_read_inode_common() read past the end of the super-root block.\n\n[ryusuke: clarify the commit title]"}],"metrics":[{"cvssV3_1":{"version":"3.1","vectorString":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:H","baseScore":7.1,"baseSeverity":"HIGH"},"scenarios":[{"lang":"en","value":"AV:L - The oversized s_inode_size is on-disk in the nilfs2 superblock; nilfs_store_disk_layout() stores it and nilfs_load_super_root() indexes the super-root buffer with NILFS_SR_CPFILE_OFFSET during local mount (nilfs_get_tree → nilfs_fill_super → init_nilfs/load_nilfs). No network protocol carries s_inode_size.\nAC:L - A crafted s_inode_size that still passes ns_inode_size <= ns_blocksize but makes NILFS_SR_BYTES(inode_size) exceed ns_blocksize (for example inode_size == blocksize) puts NILFS_SR_CPFILE_OFFSET/SUFILE_OFFSET past bh_sr->b_data, so nilfs_read_inode_common() over-reads on every mount of that image. There is no race.\nPR:N - Crafting the image needs no host account. nilfs_fs_type.fs_flags is only FS_REQUIRES_DEV (no FS_USERNS_MOUNT), so mount_capable() requires init-namespace CAP_SYS_ADMIN; that privileged mount is the victim's action and is scored as UI:R, not attacker privilege.\nUI:R - The over-read runs only in nilfs_load_super_root() from nilfs_fill_super() after a victim or automounter mounts the attacker-supplied nilfs2 image via mount/fsopen. That mount is the required user interaction.\nS:U - nilfs_read_inode_common()'s over-read of the super-root buffer_head stays in the host kernel mount path and does not cross a VM, IOMMU, or sandbox authority.\nC:H - With inode_size == ns_blocksize, NILFS_SR_CPFILE_OFFSET is 16 bytes past the super-root block, and nilfs_read_inode_common() loads a full 128-byte struct nilfs_inode (including a 56-byte i_bmap memcpy in nilfs_bmap_read) from that address. That is not a few-byte leak.\nI:N - The defect is a source over-read into in-bounds VFS inode and bmap fields; there is no store through the out-of-bounds pointer and no OOB write. Leaked i_bmap words are used only as on-disk block numbers, not as a kernel write primitive.\nA:H - A 4K block with inode_size == 4096 places the cpfile inode 16 bytes past the page-backed super-root buffer, so the 128-byte load can fault on an unmapped next linear-map page (KASAN, debug_pagealloc, page poisoning) and oops the mounting kernel."}]}],"affected":[{"product":"Linux","vendor":"Linux","defaultStatus":"unaffected","repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","programFiles":["fs/nilfs2/the_nilfs.c"],"versions":[{"version":"8a9d2191e9f43bbcd256a9a6871bd73434c83f2f","lessThan":"16df2520502867a4f34e202b89d01243d59bb8b5","status":"affected","versionType":"git"},{"version":"8a9d2191e9f43bbcd256a9a6871bd73434c83f2f","lessThan":"dcc85fc28f884038735464f6f104dda9c7dbfad6","status":"affected","versionType":"git"},{"version":"8a9d2191e9f43bbcd256a9a6871bd73434c83f2f","lessThan":"5b69ebe20d7f944c1f45177dca0c11474ac277cc","status":"affected","versionType":"git"},{"version":"8a9d2191e9f43bbcd256a9a6871bd73434c83f2f","lessThan":"7029e70cf86d5c54c0a2812479b0bee2cabcbaaa","status":"affected","versionType":"git"},{"version":"8a9d2191e9f43bbcd256a9a6871bd73434c83f2f","lessThan":"71bd64471ff583101b4a33dfc838ce29aef57960","status":"affected","versionType":"git"},{"version":"8a9d2191e9f43bbcd256a9a6871bd73434c83f2f","lessThan":"842397fdfd2e61d6470166c796f3125b6c27a162","status":"affected","versionType":"git"},{"version":"8a9d2191e9f43bbcd256a9a6871bd73434c83f2f","lessThan":"15c8559376416a84c3d8402fd8d0c89bb323d05f","status":"affected","versionType":"git"},{"version":"8a9d2191e9f43bbcd256a9a6871bd73434c83f2f","lessThan":"7cb2f76a6a2ba2130b577cb8ac13e1e46c4fc689","status":"affected","versionType":"git"}]},{"product":"Linux","vendor":"Linux","defaultStatus":"affected","repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","programFiles":["fs/nilfs2/the_nilfs.c"],"versions":[{"version":"2.6.30","status":"affected"},{"version":"0","lessThan":"2.6.30","status":"unaffected","versionType":"semver"},{"version":"5.10.270","lessThanOrEqual":"5.10.*","status":"unaffected","versionType":"semver"},{"version":"5.15.221","lessThanOrEqual":"5.15.*","status":"unaffected","versionType":"semver"},{"version":"6.1.188","lessThanOrEqual":"6.1.*","status":"unaffected","versionType":"semver"},{"version":"6.6.157","lessThanOrEqual":"6.6.*","status":"unaffected","versionType":"semver"},{"version":"6.12.110","lessThanOrEqual":"6.12.*","status":"unaffected","versionType":"semver"},{"version":"6.18.52","lessThanOrEqual":"6.18.*","status":"unaffected","versionType":"semver"},{"version":"7.2.6","lessThanOrEqual":"7.2.*","status":"unaffected","versionType":"semver"},{"version":"7.3-rc1","lessThanOrEqual":"*","status":"unaffected","versionType":"original_commit_for_fix"}]}],"cpeApplicability":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"2.6.30","versionEndExcluding":"5.10.270"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"2.6.30","versionEndExcluding":"5.15.221"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"2.6.30","versionEndExcluding":"6.1.188"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"2.6.30","versionEndExcluding":"6.6.157"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"2.6.30","versionEndExcluding":"6.12.110"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"2.6.30","versionEndExcluding":"6.18.52"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"2.6.30","versionEndExcluding":"7.2.6"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"2.6.30","versionEndExcluding":"7.3-rc1"}]}]}],"references":[{"url":"https://git.kernel.org/stable/c/16df2520502867a4f34e202b89d01243d59bb8b5"},{"url":"https://git.kernel.org/stable/c/dcc85fc28f884038735464f6f104dda9c7dbfad6"},{"url":"https://git.kernel.org/stable/c/5b69ebe20d7f944c1f45177dca0c11474ac277cc"},{"url":"https://git.kernel.org/stable/c/7029e70cf86d5c54c0a2812479b0bee2cabcbaaa"},{"url":"https://git.kernel.org/stable/c/71bd64471ff583101b4a33dfc838ce29aef57960"},{"url":"https://git.kernel.org/stable/c/842397fdfd2e61d6470166c796f3125b6c27a162"},{"url":"https://git.kernel.org/stable/c/15c8559376416a84c3d8402fd8d0c89bb323d05f"},{"url":"https://git.kernel.org/stable/c/7cb2f76a6a2ba2130b577cb8ac13e1e46c4fc689"}],"title":"nilfs2: prevent out-of-bounds read in super root block parsing","x_generator":{"engine":"bippy-1.2.0"}}}}