SB2026062928 - Improper input validation in Linux kernel nilfs2
Published: June 29, 2026
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 1 vulnerability.
1) Improper input validation (CVE-ID: CVE-2026-53320)
CWE-ID: CWE-20 - Improper input validation
CVSSv4: CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:U/U:Clear
The vulnerability allows a local user to cause a denial of service.
The vulnerability exists due to improper input validation in nilfs_ioctl_mark_blocks_dirty() when processing a crafted ioctl request. A local user can send a crafted ioctl request with bd_oblocknr set to 0 to cause a denial of service.
The issue can reach a WARN_ON path after a lookup returns -ENOENT and sets the compared block number to 0.
Remediation
Install update from vendor's website.
References
- https://git.kernel.org/stable/c/4525658002be3ad310b16bf8db48c8adb6a55d32
- https://git.kernel.org/stable/c/65e07964b4b2daf9a54e686cf0fa72d74a9648a8
- https://git.kernel.org/stable/c/94094e70fe292c9566502772d4d4d6d6a99204b1
- https://git.kernel.org/stable/c/9472d37799a0b9ff9b99639f35961ac2f0b3c9be
- https://git.kernel.org/stable/c/b88f905d4449b70da6bda547be546e365e44352e
- https://git.kernel.org/stable/c/be3e5d10643d3be1cbac9d9939f220a99253f980
- https://git.kernel.org/stable/c/e0a0c4903cbba351f0f5b5d104960d3a5b23202f
- https://git.kernel.org/stable/c/e5ff0ba4b6983cdbcc826efc201e7179ece5d46f