CVE-2026-55392

MEDIUM

NILFS utilities - Undefined Behavior and Out-of-Memory via Unvalidated s_log_block_size

Title source: cna
STIX 2.1

Description

NILFS utilities through 2.3.0, fixed in commit 26efb5d, nilfs_sb_is_valid() function fails to validate s_log_block_size field in NILFS2 superblock before bit-shift operations. Attackers supplying crafted NILFS2 images trigger undefined behavior through oversized shifts or out-of-memory conditions, crashing tools like nilfs-tune and dumpseg.

Scores

CVSS v3 5.5
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-1284
Status published
Products (2)
nilfs-dev/nilfs-utils < 2.3.0
nilfs-dev/nilfs-utils 26efb5daff0757365101035145331b0a5a85d9d9
Published Jun 18, 2026
Tracked Since Jun 19, 2026