Infinite loop in Linux kernel - CVE-2026-90420
Published: September 18, 2026
Vulnerability details
The vulnerability allows a local user to cause a denial of service.
The vulnerability exists due to improper handling of terminal errors in nilfs_clean_segments() when the cleaner ioctl encounters repeated -EROFS errors from nilfs_segctor_construct(). A local user can invoke the cleaner ioctl to cause a denial of service.
The issue can occur when the device is remounted read-only after an I/O error.
Affected software
How to mitigate CVE-2026-90420
External References
- https://git.kernel.org/stable/c/1fc6df85b4954b6fda9c351843aaca3c06f66d8d
- https://git.kernel.org/stable/c/217b967ad7887a3e1ebc08f46f6484e081acd4b4
- https://git.kernel.org/stable/c/3bcdbdaac884a4baa59716cf9bd9470c75276e2d
- https://git.kernel.org/stable/c/8cea0bc78ac64cb88da49c07f80bf2cf9fb7aff8
- https://git.kernel.org/stable/c/c07e5ad6539e7e9350d5c65cbf8adb69d1711b15
- https://git.kernel.org/stable/c/ce5a5ad1a8330a2fcfdd9ec2ab341be739e89a18
- https://git.kernel.org/stable/c/d7afca8e4efbf4c455b4663c29ae59fde2f1b671
- https://git.kernel.org/stable/c/e3e9367dae1a6392cbb14ab0b2ab5edbf39735c3