nilfs2: fix slab-out-of-bounds in nilfs_direct_propagate after truncation
Summary
| CVE | CVE-2026-89723 |
| State | PUBLISHED |
| Assigner | Linux |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2026-09-11 20:20:01 UTC |
| Updated | 2026-09-11 20:20:01 UTC |
| Description | In the Linux kernel, the following vulnerability has been resolved:
nilfs2: fix slab-out-of-bounds in nilfs_direct_propagate after truncation
Shuangpeng Bai reported that KASAN detected a slab-out-of-bounds error
in nilfs_direct_propagate() during testing.
Analysis revealed that after truncating a file, a node block immediately
below the B-tree root was not deleted. Instead, it remained in the B-tree
node cache in a dirty state. The log writer subsequently detected this
block and incorrectly invoked nilfs_direct_propagate() on it, which is
designed to handle only data blocks in direct mapping.
B-tree nodes in the cache are managed by virtual block numbers, and their
logical keys typically exceed the range expected by direct mapping.
Consequently, processing such a node as a direct mapping entry triggers
a slab-out-of-bounds access.
The root cause is that when a B-tree mapping collapses into a direct
mapping during truncation, an intermediate node block pointed to by the
root node is left behind as garbage instead of being explicitly deleted.
This resolves the issue by adding a nilfs_btree_discard() operation
to delete the remaining intermediate node block during the conversion.
A 'deform' flag is added to the bop_delete interface to explicitly signal
that the deletion is part of a mapping transformation. This allows the
B-tree mapping implementation to perform the necessary cleanup and
discarding of the residual node structure that would be otherwise be left
orphaned after the transition. |
Vendor Declared Affected Products
| Source | Vendor | Product | Version | Platforms |
|---|
| CNA |
Linux |
Linux |
affected 36a580eb489f54d81a0534974962e732a314b999 5d3783c451a546373662ee11ec17019273e68034 git |
Not specified |
| CNA |
Linux |
Linux |
affected 36a580eb489f54d81a0534974962e732a314b999 448636c745a3f3b8582a0b8ce718c890a11c0fa9 git |
Not specified |
| CNA |
Linux |
Linux |
affected 36a580eb489f54d81a0534974962e732a314b999 28362e8ce51377afdec1782e661e808328a10514 git |
Not specified |
| CNA |
Linux |
Linux |
affected 36a580eb489f54d81a0534974962e732a314b999 45662dedb8f272ef7f16e69f13424c4bd0399240 git |
Not specified |
| CNA |
Linux |
Linux |
affected 2.6.30 |
Not specified |
| CNA |
Linux |
Linux |
unaffected 2.6.30 semver |
Not specified |
| CNA |
Linux |
Linux |
unaffected 6.12.109 6.12.* semver |
Not specified |
| CNA |
Linux |
Linux |
unaffected 6.18.50 6.18.* semver |
Not specified |
| CNA |
Linux |
Linux |
unaffected 7.2.4 7.2.* semver |
Not specified |
| CNA |
Linux |
Linux |
unaffected 7.3-rc1 * original_commit_for_fix |
Not specified |
References
| Reference | Source | Link | Tags |
|---|
| git.kernel.org/stable/c/45662dedb8f272ef7f16e69f13424c4bd0399240 |
416baaa9-dc9f-4396-8d5f-8c081fb06d67 |
git.kernel.org |
|
| git.kernel.org/stable/c/5d3783c451a546373662ee11ec17019273e68034 |
416baaa9-dc9f-4396-8d5f-8c081fb06d67 |
git.kernel.org |
|
| git.kernel.org/stable/c/448636c745a3f3b8582a0b8ce718c890a11c0fa9 |
416baaa9-dc9f-4396-8d5f-8c081fb06d67 |
git.kernel.org |
|
| git.kernel.org/stable/c/28362e8ce51377afdec1782e661e808328a10514 |
416baaa9-dc9f-4396-8d5f-8c081fb06d67 |
git.kernel.org |
|
| CVE Program record |
CVE.ORG |
www.cve.org |
canonical |
| NVD vulnerability detail |
NVD |
nvd.nist.gov |
canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.