« Volver al listado

CVE-2026-80807

Estado: RecibidaSin puntuar—

In the Linux kernel, the following vulnerability has been resolved:

nilfs2: reject invalid block index in GC ioctl

Syzbot reported list corruption caused by a double list_add_tail() call on bh->b_assoc_buffers within nilfs_lookup_dirty_data_buffers().

Analysis revealed that the root cause was the insertion of a page/folio with a page index of ULONG_MAX into the page cache via the GC ioctl. filemap_get_folios_tag(), called by nilfs_lookup_dirty_data_buffers(), repeatedly detects a dirty folio with a page index of ULONG_MAX due to index wrap-around, leading to duplicate processing of dirty buffers.

Leer descripción completaMostrar menos

As a preparatory step, the GC ioctl loads the page/folio of the block to be moved during GC and inserts it into the page cache based on information in the nilfs_vdesc structure passed as an argument. Normally, this does not cause issues because the user-space GC library configures the nilfs_vdesc structure properly. However, since there is no range check on the parameters determining the page index, a request with artificially crafted parameters -- such as those generated by Syzbot -- can result in a page/folio being inserted with a page index of ULONG_MAX, triggering the above problem.

This resolves the issue by checking the ranges of 'vd_offset' and 'vd_vblocknr' in the nilfs_vdesc structure that determine the page index, thereby preventing the invalid page/folio insertions.

CVSS

NVD no ha asignado puntuación CVSS a esta CVE (habitual desde el cambio de política de abril de 2026).

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (1)

⚠ Inferidas por IA a partir de la descripción — NVD aún no ha analizado esta CVE; no son CPE verificados.

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2026-80807",
  "cveTags": [],
  "metrics": {},
  "affected": [
    {
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
      "affectedData": [
        {
          "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
          "vendor": "Linux",
          "product": "Linux",
          "versions": [
            {
              "status": "affected",
              "version": "7942b919f7321f95a777d396ff7894a7a83dc9b0",
              "lessThan": "898404cdf882d7b54f1132f75570984ca3214796",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "7942b919f7321f95a777d396ff7894a7a83dc9b0",
              "lessThan": "ba8a8b563a28d358c45c62a306d421434a058648",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "7942b919f7321f95a777d396ff7894a7a83dc9b0",
              "lessThan": "3bd064ccc70b85f9a3d53aece29dc8473be5a226",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "7942b919f7321f95a777d396ff7894a7a83dc9b0",
              "lessThan": "a5e776e2937581d67ec5b9b4d27b0f70d7baa6b1",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "7942b919f7321f95a777d396ff7894a7a83dc9b0",
              "lessThan": "68aa9ab6f8f2895713aa6ddf781463ed8ea5ba44",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "7942b919f7321f95a777d396ff7894a7a83dc9b0",
              "lessThan": "e447f7edb99bd00cec63d6f3049e2e5074946f71",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "7942b919f7321f95a777d396ff7894a7a83dc9b0",
              "lessThan": "ec6ddf271dfa4c7e3147bc2c8b2bad4315f316a1",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "7942b919f7321f95a777d396ff7894a7a83dc9b0",
              "lessThan": "fbcfb75c20d71a5b542ad4ac3b79d10b997c8152",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "7942b919f7321f95a777d396ff7894a7a83dc9b0",
              "lessThan": "a1735eae55448bc79c2da6593455791e886f6ed8",
              "versionType": "git"
            }
          ],
          "programFiles": [
            "fs/nilfs2/ioctl.c"
          ],
          "defaultStatus": "unaffected"
        },
        {
          "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
          "vendor": "Linux",
          "product": "Linux",
          "versions": [
            {
              "status": "affected",
              "version": "2.6.30"
            },
            {
              "status": "unaffected",
              "version": "0",
              "lessThan": "2.6.30",
              "versionType": "semver"
            },
            {
              "status": "unaffected",
              "version": "5.10.269",
              "versionType": "semver",
              "lessThanOrEqual": "5.10.*"
            },
            {
              "status": "unaffected",
              "version": "5.15.220",
              "versionType": "semver",
              "lessThanOrEqual": "5.15.*"
            },
            {
              "status": "unaffected",
              "version": "6.1.187",
              "versionType": "semver",
              "lessThanOrEqual": "6.1.*"
            },
            {
              "status": "unaffected",
              "version": "6.6.156",
              "versionType": "semver",
              "lessThanOrEqual": "6.6.*"
            },
            {
              "status": "unaffected",
              "version": "6.12.108",
              "versionType": "semver",
              "lessThanOrEqual": "6.12.*"
            },
            {
              "status": "unaffected",
              "version": "6.18.47",
              "versionType": "semver",
              "lessThanOrEqual": "6.18.*"
            },
            {
              "status": "unaffected",
              "version": "7.1.11",
              "versionType": "semver",
              "lessThanOrEqual": "7.1.*"
            },
            {
              "status": "unaffected",
              "version": "7.2.1",
              "versionType": "semver",
              "lessThanOrEqual": "7.2.*"
            },
            {
              "status": "unaffected",
              "version": "7.3-rc1",
              "versionType": "original_commit_for_fix",
              "lessThanOrEqual": "*"
            }
          ],
          "programFiles": [
            "fs/nilfs2/ioctl.c"
          ],
          "defaultStatus": "affected"
        }
      ]
    }
  ],
  "published": "2026-09-04T16:18:07.810",
  "references": [
    {
      "url": "https://git.kernel.org/stable/c/3bd064ccc70b85f9a3d53aece29dc8473be5a226",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/68aa9ab6f8f2895713aa6ddf781463ed8ea5ba44",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/898404cdf882d7b54f1132f75570984ca3214796",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/a1735eae55448bc79c2da6593455791e886f6ed8",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/a5e776e2937581d67ec5b9b4d27b0f70d7baa6b1",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/ba8a8b563a28d358c45c62a306d421434a058648",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/e447f7edb99bd00cec63d6f3049e2e5074946f71",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/ec6ddf271dfa4c7e3147bc2c8b2bad4315f316a1",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/fbcfb75c20d71a5b542ad4ac3b79d10b997c8152",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    }
  ],
  "vulnStatus": "Received",
  "descriptions": [
    {
      "lang": "en",
      "value": "In the Linux kernel, the following vulnerability has been resolved:\n\nnilfs2: reject invalid block index in GC ioctl\n\nSyzbot reported list corruption caused by a double list_add_tail() call on\nbh->b_assoc_buffers within nilfs_lookup_dirty_data_buffers().\n\nAnalysis revealed that the root cause was the insertion of a page/folio\nwith a page index of ULONG_MAX into the page cache via the GC ioctl.\nfilemap_get_folios_tag(), called by nilfs_lookup_dirty_data_buffers(),\nrepeatedly detects a dirty folio with a page index of ULONG_MAX due to\nindex wrap-around, leading to duplicate processing of dirty buffers.\n\nAs a preparatory step, the GC ioctl loads the page/folio of the block to\nbe moved during GC and inserts it into the page cache based on information\nin the nilfs_vdesc structure passed as an argument.  Normally, this does\nnot cause issues because the user-space GC library configures the\nnilfs_vdesc structure properly.  However, since there is no range check on\nthe parameters determining the page index, a request with artificially\ncrafted parameters -- such as those generated by Syzbot -- can result in a\npage/folio being inserted with a page index of ULONG_MAX, triggering the\nabove problem.\n\nThis resolves the issue by checking the ranges of 'vd_offset' and\n'vd_vblocknr' in the nilfs_vdesc structure that determine the page index,\nthereby preventing the invalid page/folio insertions."
    }
  ],
  "lastModified": "2026-09-04T16:18:07.810",
  "sourceIdentifier": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
}