« Volver al listado

CVE-2026-31577

Estado: ModificadaMedia (5.5)—

In the Linux kernel, the following vulnerability has been resolved:

nilfs2: fix NULL i_assoc_inode dereference in nilfs_mdt_save_to_shadow_map

The DAT inode's btree node cache (i_assoc_inode) is initialized lazily during btree operations. However, nilfs_mdt_save_to_shadow_map() assumes i_assoc_inode is already initialized when copying dirty pages to the shadow map during GC.

If NILFS_IOCTL_CLEAN_SEGMENTS is called immediately after mount before any btree operation has occurred on the DAT inode, i_assoc_inode is NULL leading to a general protection fault.

Fix this by calling nilfs_attach_btree_node_cache() on the DAT inode in nilfs_dat_read() at mount time, ensuring i_assoc_inode is always initialized before any GC operation can use it.

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (1)

CWE

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2026-31577",
  "cveTags": [],
  "metrics": {
    "cvssMetricV31": [
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "scope": "UNCHANGED",
          "version": "3.1",
          "baseScore": 5.5,
          "attackVector": "LOCAL",
          "baseSeverity": "MEDIUM",
          "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H",
          "integrityImpact": "NONE",
          "userInteraction": "NONE",
          "attackComplexity": "LOW",
          "availabilityImpact": "HIGH",
          "privilegesRequired": "LOW",
          "confidentialityImpact": "NONE"
        },
        "impactScore": 3.6,
        "exploitabilityScore": 1.8
      }
    ]
  },
  "affected": [
    {
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
      "affectedData": [
        {
          "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
          "vendor": "Linux",
          "product": "Linux",
          "versions": [
            {
              "status": "affected",
              "version": "d626fcdabea2258be395a775bdbe09270e9bf73d",
              "lessThan": "6637bbcfb59df5b732a79e5ab1a74886a0b93d59",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "d05cc5395e36711edad8bdef6945f138d8a7097b",
              "lessThan": "837c7a59fb58f81b0db33848357f6a5d0d1250ad",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "e897be17a441fa637cd166fc3de1445131e57692",
              "lessThan": "7902b1df1520a0880bcda7a3704cfacd17905a83",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "e897be17a441fa637cd166fc3de1445131e57692",
              "lessThan": "7318e3549518ce8f14776a489d86488d80d7e2c8",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "e897be17a441fa637cd166fc3de1445131e57692",
              "lessThan": "449ec5fc99f45974525ba9eea16b6670c45cd363",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "e897be17a441fa637cd166fc3de1445131e57692",
              "lessThan": "c36e206f302f1ddefed92d09ecbba070e1ae079e",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "e897be17a441fa637cd166fc3de1445131e57692",
              "lessThan": "41de342278ae025c99cc8d33648773f05e306cf1",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "e897be17a441fa637cd166fc3de1445131e57692",
              "lessThan": "97fb7afec404912d967a7d4715f37742666b3084",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "e897be17a441fa637cd166fc3de1445131e57692",
              "lessThan": "4a4e0328edd9e9755843787d28f16dd4165f8b48",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "6c3da8c0a35bbafe359d9166269d5590f29664de",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "605babb979c213737618b1c837e89624e5ab11fd",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "307d021b1a7f33048b624f7aaeaa75e3eae571f1",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "1829b24a36ca12ca95b96d5478faeff40c17f2b6",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "5.10.118",
              "lessThan": "5.10.258",
              "versionType": "semver"
            },
            {
              "status": "affected",
              "version": "5.15.42",
              "lessThan": "5.15.209",
              "versionType": "semver"
            },
            {
              "status": "affected",
              "version": "4.14.296",
              "lessThan": "4.15",
              "versionType": "semver"
            },
            {
              "status": "affected",
              "version": "4.19.245",
              "lessThan": "4.20",
              "versionType": "semver"
            },
            {
              "status": "affected",
              "version": "5.4.196",
              "lessThan": "5.5",
              "versionType": "semver"
            },
            {
              "status": "affected",
              "version": "5.17.10",
              "lessThan": "5.18",
              "versionType": "semver"
            }
          ],
          "programFiles": [
            "fs/nilfs2/dat.c"
          ],
          "defaultStatus": "unaffected"
        },
        {
          "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
          "vendor": "Linux",
          "product": "Linux",
          "versions": [
            {
              "status": "affected",
              "version": "5.18"
            },
            {
              "status": "unaffected",
              "version": "0",
              "lessThan": "5.18",
              "versionType": "semver"
            },
            {
              "status": "unaffected",
              "version": "5.10.258",
              "versionType": "semver",
              "lessThanOrEqual": "5.10.*"
            },
            {
              "status": "unaffected",
              "version": "5.15.209",
              "versionType": "semver",
              "lessThanOrEqual": "5.15.*"
            },
            {
              "status": "unaffected",
              "version": "6.1.175",
              "versionType": "semver",
              "lessThanOrEqual": "6.1.*"
            },
            {
              "status": "unaffected",
              "version": "6.6.136",
              "versionType": "semver",
              "lessThanOrEqual": "6.6.*"
            },
            {
              "status": "unaffected",
              "version": "6.12.83",
              "versionType": "semver",
              "lessThanOrEqual": "6.12.*"
            },
            {
              "status": "unaffected",
              "version": "6.18.24",
              "versionType": "semver",
              "lessThanOrEqual": "6.18.*"
            },
            {
              "status": "unaffected",
              "version": "6.19.14",
              "versionType": "semver",
              "lessThanOrEqual": "6.19.*"
            },
            {
              "status": "unaffected",
              "version": "7.0.1",
              "versionType": "semver",
              "lessThanOrEqual": "7.0.*"
            },
            {
              "status": "unaffected",
              "version": "7.1",
              "versionType": "original_commit_for_fix",
              "lessThanOrEqual": "*"
            }
          ],
          "programFiles": [
            "fs/nilfs2/dat.c"
          ],
          "defaultStatus": "affected"
        }
      ]
    }
  ],
  "published": "2026-04-24T15:16:32.347",
  "references": [
    {
      "url": "https://git.kernel.org/stable/c/41de342278ae025c99cc8d33648773f05e306cf1",
      "tags": [
        "Patch"
      ],
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/449ec5fc99f45974525ba9eea16b6670c45cd363",
      "tags": [
        "Patch"
      ],
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/4a4e0328edd9e9755843787d28f16dd4165f8b48",
      "tags": [
        "Patch"
      ],
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/6637bbcfb59df5b732a79e5ab1a74886a0b93d59",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/7318e3549518ce8f14776a489d86488d80d7e2c8",
      "tags": [
        "Patch"
      ],
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/7902b1df1520a0880bcda7a3704cfacd17905a83",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/837c7a59fb58f81b0db33848357f6a5d0d1250ad",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/97fb7afec404912d967a7d4715f37742666b3084",
      "tags": [
        "Patch"
      ],
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/c36e206f302f1ddefed92d09ecbba070e1ae079e",
      "tags": [
        "Patch"
      ],
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    }
  ],
  "vulnStatus": "Modified",
  "weaknesses": [
    {
      "type": "Primary",
      "source": "nvd@nist.gov",
      "description": [
        {
          "lang": "en",
          "value": "CWE-476"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "In the Linux kernel, the following vulnerability has been resolved:\n\nnilfs2: fix NULL i_assoc_inode dereference in nilfs_mdt_save_to_shadow_map\n\nThe DAT inode's btree node cache (i_assoc_inode) is initialized lazily\nduring btree operations. However, nilfs_mdt_save_to_shadow_map()\nassumes i_assoc_inode is already initialized when copying dirty pages\nto the shadow map during GC.\n\nIf NILFS_IOCTL_CLEAN_SEGMENTS is called immediately after mount before\nany btree operation has occurred on the DAT inode, i_assoc_inode is\nNULL leading to a general protection fault.\n\nFix this by calling nilfs_attach_btree_node_cache() on the DAT inode\nin nilfs_dat_read() at mount time, ensuring i_assoc_inode is always\ninitialized before any GC operation can use it."
    }
  ],
  "lastModified": "2026-06-17T10:34:00.707",
  "configurations": [
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "14109CEF-714B-4029-A318-97AA58A01833",
              "versionEndExcluding": "6.6.136"
            },
            {
              "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "7F0AE5B5-23AC-4DCC-B37A-51CA1DAE7BA8",
              "versionEndExcluding": "6.12.83",
              "versionStartIncluding": "6.7"
            },
            {
              "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "8126B8B8-6D0B-4443-86C1-672AEE893555",
              "versionEndExcluding": "6.18.24",
              "versionStartIncluding": "6.13"
            },
            {
              "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "D6A8A074-BBF4-4803-ABED-519A839435BB",
              "versionEndExcluding": "6.19.14",
              "versionStartIncluding": "6.19"
            },
            {
              "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "9B5888AB-7403-4335-89E4-21CC0B48366A",
              "versionEndExcluding": "7.0.1",
              "versionStartIncluding": "7.0"
            }
          ],
          "operator": "OR"
        }
      ]
    }
  ],
  "sourceIdentifier": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
}