Junglewise Threat Intelligence

CVE-2026-90418: Linux kernel nilfs2 BUG in nilfs_copy_dirty_pages on dirty state mismatch

CVE-2026-90418 · Severity: info · Published 2026-09-17

Technologies: Linux Kernel. Vendors: Linux.

Executive brief

The nilfs2 filesystem component in the Linux kernel can crash when copying metadata pages during certain error conditions. When the filesystem detects corruption and transitions to read-only mode, page dirty flags may be cleared asynchronously, causing a kernel panic. This fix prevents the crash by gracefully handling the condition instead of triggering a fatal kernel BUG.

Technical details

This vulnerability is a kernel panic (BUG) in the nilfs_copy_dirty_pages() function within the nilfs2 filesystem implementation. The root cause is a race condition where folio/page dirty flags can be cleared asynchronously after the filesystem detects metadata corruption and transitions to read-only mode. When nilfs_copy_dirty_pages() retrieves a folio that has lost its dirty status unexpectedly, it triggers a fatal kernel assertion. The fix changes the behavior to check if the filesystem is read-only and return an -EROFS error code instead of crashing, or issue a WARN_ONCE() warning if the filesystem is still writable. The vulnerability requires local access and affects kernels with the prior commit that introduced asynchronous dirty flag clearing after corruption detection.

Affected products

  • Linux Linux kernel Multiple kernel versions (affected by prior commit, patched in 2026-07 onwards)

Timeline

  • 2026-09-17: disclosed: CVE-2026-90418 published
  • 2026-07-20: patched: Fix committed by Ryusuke Konishi
  • 2026-09-14: patched: Fix merged to stable kernel tree by Greg Kroah-Hartman

References

Related threats