{"dataType":"CVE_RECORD","dataVersion":"5.2","cveMetadata":{"cveId":"CVE-2026-90420","assignerOrgId":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","state":"PUBLISHED","assignerShortName":"Linux","dateReserved":"2026-09-11T19:38:34.813Z","datePublished":"2026-09-17T16:09:44.558Z","dateUpdated":"2026-09-17T16:09:44.558Z"},"containers":{"cna":{"providerMetadata":{"orgId":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","shortName":"Linux","dateUpdated":"2026-09-17T16:09:44.558Z"},"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nnilfs2: fix infinite loop in nilfs_clean_segments()\n\nsyzbot reported a hung task in nilfs_transaction_begin(). This occurs\nbecause the cleaner ioctl falls into an infinite loop if\nnilfs_segctor_construct() repeatedly returns -EROFS (e.g. the device\nis remounted as read-only after an I/O error).\n\nCurrently in nilfs_clean_segments(), if err is non-zero, it logs the\nerror and sleeps but doesn't abort when it encounters a terminal error\nlike -EROFS. This causes the thread to loop forever.\n\nFix this by breaking out of the loop if nilfs_segctor_construct()\nreturns -EROFS. This matches the behaviour in\nnilfs_segctor_write_out(), which also handles -EROFS."}],"affected":[{"product":"Linux","vendor":"Linux","defaultStatus":"unaffected","repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","programFiles":["fs/nilfs2/segment.c"],"versions":[{"version":"9ff05123e3bfbb1d2b68ba1d9bf1f7d1dffc1453","lessThan":"e3e9367dae1a6392cbb14ab0b2ab5edbf39735c3","status":"affected","versionType":"git"},{"version":"9ff05123e3bfbb1d2b68ba1d9bf1f7d1dffc1453","lessThan":"217b967ad7887a3e1ebc08f46f6484e081acd4b4","status":"affected","versionType":"git"},{"version":"9ff05123e3bfbb1d2b68ba1d9bf1f7d1dffc1453","lessThan":"3bcdbdaac884a4baa59716cf9bd9470c75276e2d","status":"affected","versionType":"git"},{"version":"9ff05123e3bfbb1d2b68ba1d9bf1f7d1dffc1453","lessThan":"d7afca8e4efbf4c455b4663c29ae59fde2f1b671","status":"affected","versionType":"git"},{"version":"9ff05123e3bfbb1d2b68ba1d9bf1f7d1dffc1453","lessThan":"c07e5ad6539e7e9350d5c65cbf8adb69d1711b15","status":"affected","versionType":"git"},{"version":"9ff05123e3bfbb1d2b68ba1d9bf1f7d1dffc1453","lessThan":"1fc6df85b4954b6fda9c351843aaca3c06f66d8d","status":"affected","versionType":"git"},{"version":"9ff05123e3bfbb1d2b68ba1d9bf1f7d1dffc1453","lessThan":"8cea0bc78ac64cb88da49c07f80bf2cf9fb7aff8","status":"affected","versionType":"git"},{"version":"9ff05123e3bfbb1d2b68ba1d9bf1f7d1dffc1453","lessThan":"ce5a5ad1a8330a2fcfdd9ec2ab341be739e89a18","status":"affected","versionType":"git"}]},{"product":"Linux","vendor":"Linux","defaultStatus":"affected","repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","programFiles":["fs/nilfs2/segment.c"],"versions":[{"version":"2.6.30","status":"affected"},{"version":"0","lessThan":"2.6.30","status":"unaffected","versionType":"semver"},{"version":"5.10.270","lessThanOrEqual":"5.10.*","status":"unaffected","versionType":"semver"},{"version":"5.15.221","lessThanOrEqual":"5.15.*","status":"unaffected","versionType":"semver"},{"version":"6.1.188","lessThanOrEqual":"6.1.*","status":"unaffected","versionType":"semver"},{"version":"6.6.157","lessThanOrEqual":"6.6.*","status":"unaffected","versionType":"semver"},{"version":"6.12.110","lessThanOrEqual":"6.12.*","status":"unaffected","versionType":"semver"},{"version":"6.18.52","lessThanOrEqual":"6.18.*","status":"unaffected","versionType":"semver"},{"version":"7.2.6","lessThanOrEqual":"7.2.*","status":"unaffected","versionType":"semver"},{"version":"7.3-rc1","lessThanOrEqual":"*","status":"unaffected","versionType":"original_commit_for_fix"}]}],"cpeApplicability":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"2.6.30","versionEndExcluding":"5.10.270"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"2.6.30","versionEndExcluding":"5.15.221"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"2.6.30","versionEndExcluding":"6.1.188"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"2.6.30","versionEndExcluding":"6.6.157"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"2.6.30","versionEndExcluding":"6.12.110"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"2.6.30","versionEndExcluding":"6.18.52"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"2.6.30","versionEndExcluding":"7.2.6"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"2.6.30","versionEndExcluding":"7.3-rc1"}]}]}],"references":[{"url":"https://git.kernel.org/stable/c/e3e9367dae1a6392cbb14ab0b2ab5edbf39735c3"},{"url":"https://git.kernel.org/stable/c/217b967ad7887a3e1ebc08f46f6484e081acd4b4"},{"url":"https://git.kernel.org/stable/c/3bcdbdaac884a4baa59716cf9bd9470c75276e2d"},{"url":"https://git.kernel.org/stable/c/d7afca8e4efbf4c455b4663c29ae59fde2f1b671"},{"url":"https://git.kernel.org/stable/c/c07e5ad6539e7e9350d5c65cbf8adb69d1711b15"},{"url":"https://git.kernel.org/stable/c/1fc6df85b4954b6fda9c351843aaca3c06f66d8d"},{"url":"https://git.kernel.org/stable/c/8cea0bc78ac64cb88da49c07f80bf2cf9fb7aff8"},{"url":"https://git.kernel.org/stable/c/ce5a5ad1a8330a2fcfdd9ec2ab341be739e89a18"}],"title":"nilfs2: fix infinite loop in nilfs_clean_segments()","x_generator":{"engine":"bippy-1.2.0"}}}}