CVE-2026-55392
MEDIUMNILFS utilities - Undefined Behavior and Out-of-Memory via Unvalidated s_log_block_size
Title source: cnaDescription
NILFS utilities through 2.3.0, fixed in commit 26efb5d, nilfs_sb_is_valid() function fails to validate s_log_block_size field in NILFS2 superblock before bit-shift operations. Attackers supplying crafted NILFS2 images trigger undefined behavior through oversized shifts or out-of-memory conditions, crashing tools like nilfs-tune and dumpseg.
References (2)
Core 2
Core References
Patch patch
Patch Commit
https://github.com/nilfs-dev/nilfs-utils/commit/26efb5daff0757365101035145331b0a5a85d9d9
Scores
CVSS v3
5.5
Attack Vector
LOCAL
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
CISA SSVC
Vulnrichment
Exploitation
none
Automatable
no
Technical Impact
partial
Details
CWE
CWE-1284
Status
published
Products (2)
nilfs-dev/nilfs-utils
< 2.3.0
nilfs-dev/nilfs-utils
26efb5daff0757365101035145331b0a5a85d9d9
Published
Jun 18, 2026
Tracked Since
Jun 19, 2026