SB20260905149 - Improper Validation of Specified Quantity in Input in Linux kernel nilfs2
Published: September 5, 2026
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 1 vulnerability.
1) Improper Validation of Specified Quantity in Input (CVE-ID: CVE-2026-80807)
CWE-ID: CWE-1284 - Improper Validation of Specified Quantity in Input
CVSSv4: 0 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a local user to cause list corruption.
The vulnerability exists due to improper range validation in the nilfs2 GC ioctl when processing crafted virtual block descriptors. A local user can submit a crafted GC ioctl request to cause list corruption.
The crafted descriptor can specify an invalid virtual block number or offset that results in a page index of ULONG_MAX.
Remediation
Install update from vendor's website.
References
- https://git.kernel.org/stable/c/3bd064ccc70b85f9a3d53aece29dc8473be5a226
- https://git.kernel.org/stable/c/68aa9ab6f8f2895713aa6ddf781463ed8ea5ba44
- https://git.kernel.org/stable/c/898404cdf882d7b54f1132f75570984ca3214796
- https://git.kernel.org/stable/c/a1735eae55448bc79c2da6593455791e886f6ed8
- https://git.kernel.org/stable/c/a5e776e2937581d67ec5b9b4d27b0f70d7baa6b1
- https://git.kernel.org/stable/c/ba8a8b563a28d358c45c62a306d421434a058648
- https://git.kernel.org/stable/c/e447f7edb99bd00cec63d6f3049e2e5074946f71
- https://git.kernel.org/stable/c/ec6ddf271dfa4c7e3147bc2c8b2bad4315f316a1
- https://git.kernel.org/stable/c/fbcfb75c20d71a5b542ad4ac3b79d10b997c8152