SB20260727212 - Improper input validation in Linux kernel nilfs2
Published: July 27, 2026
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 1 vulnerability.
1) Improper input validation (CVE-ID: CVE-2026-64359)
CWE-ID: CWE-20 - Improper input validation
CVSSv4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a local user to cause a denial of service.
The vulnerability exists due to improper input validation in nilfs_clean_segments when processing user-supplied segment numbers through the CLEAN_SEGMENTS ioctl. A local user can submit out-of-range segment numbers to cause a denial of service.
The issue can hold ns_segctor_sem long enough to block concurrent filesystem operations such as chmod().
Remediation
Install update from vendor's website.
References
- https://git.kernel.org/stable/c/0789f0a6710713254a08f3a7d2ecbb6d1cbcf0aa
- https://git.kernel.org/stable/c/0e7a690fe435f8d5ea3feb7c1d8d73ba7e8b8aa9
- https://git.kernel.org/stable/c/223463c488b0554212a94de971ea538eb2805fc7
- https://git.kernel.org/stable/c/286f77d002a337735c0846d7480a82d9cda2aa31
- https://git.kernel.org/stable/c/39607452b1400c7bf748f15122df4d058b768c5b
- https://git.kernel.org/stable/c/3ed388ec3b8922383d1e2d4432d7bd4cbbf8364e
- https://git.kernel.org/stable/c/876c98e0fc65f071680c03c2e2ee3ef7ff9ca078
- https://git.kernel.org/stable/c/d26aef771b4f6923da9f89d6d5b70d8def5853de