GHSA-mf3g-x95g-wcp3HighCVSS 7.1

In the Linux kernel, the following vulnerability has been resolved: nilfs2: prevent out-of...

Published
September 17, 2026
Last Modified
September 18, 2026

🔗 CVE IDs covered (1)

📋 Description

In the Linux kernel, the following vulnerability has been resolved:

nilfs2: prevent out-of-bounds read in super root block parsing

super-root inode metadata size is trusted before nilfs_read_inode_common().

Reject super-root inode sizes whose computed on-disk footprint exceeds the filesystem block size. This prevents malformed filesystem images from making nilfs_read_inode_common() read past the end of the super-root block.

[ryusuke: clarify the commit title]

🔗 References (10)