HIGH Introduced in 2.6.30
nilfs2 SuperRoot OOB
CVE-2026-90419
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:H
KernelScan AI6.0MEDIUM
01Description
In the Linux kernel, the following vulnerability has been resolved: nilfs2: prevent out-of-bounds read in super root block parsing super-root inode metadata size is trusted before nilfs_read_inode_common(). Reject super-root inode sizes whose computed on-disk footprint exceeds the filesystem block size. This prevents malformed filesystem images from making nilfs_read_inode_common() read past the end of the super-root block. [ryusuke: clarify the commit title]
02KernelScan AI Analysis
Risk summary
A malformed nilfs2 filesystem image can specify an inode size that causes the kernel to read past the end of a block buffer during super-root parsing, leaking adjacent kernel memory or crashing the system. Triggering the bug requires mounting the crafted image, which needs real CAP_SYS_ADMIN in the init namespace — either via physical removable media or a privileged user performing a manual mount. Products that never mount nilfs2 images are not affected.
Vulnerability analysis
When mounting a nilfs2 filesystem, the inode size field from the on-disk superblock is trusted without verifying that the computed on-disk footprint of the super-root inode fits within a single filesystem block. A crafted image can set an inode size large enough that the inode parsing routine reads beyond the end of the allocated block buffer, exposing adjacent kernel memory or hitting unmapped pages and crashing the kernel. The fix adds a validation check during filesystem layout setup that rejects any inode size whose computed super-root size exceeds the block size, returning an error before the vulnerable parsing path is reached. This bug is only reachable by mounting a crafted nilfs2 filesystem image, which requires real CAP_SYS_ADMIN in the init namespace — nilfs2 is not mountable inside user namespaces — so the realistic trigger is either physical insertion of removable media or a privileged user manually mounting a malicious image.
Lifecycle
03Fix Versions
| Branch | Introduced | Fixed in | Patch commit |
|---|---|---|---|
| 6.1 | 2.6.30 | 6.1.188 | 5b69ebe20d7f |
| 6.6 | 2.6.30 | 6.6.157 | 7029e70cf86d |
| 6.12 | 2.6.30 | 6.12.110 | 71bd64471ff5 |
| 7.2 | 2.6.30 | 7.2.6 | 15c855937641 |
| mainline | 2.6.30 | 7.3-rc1 | 7cb2f76a6a2b |
| 5.10 | 2.6.30 | 5.10.270 | 16df25205028 |
| 6.18 | 2.6.30 | 6.18.52 | 842397fdfd2e |
| 5.15 | 2.6.30 | 5.15.221 | dcc85fc28f88 |