Executive brief
The nilfs2 filesystem component in the Linux kernel can crash when copying metadata pages during certain error conditions. When the filesystem detects corruption and transitions to read-only mode, page dirty flags may be cleared asynchronously, causing a kernel panic. This fix prevents the crash by gracefully handling the condition instead of triggering a fatal kernel BUG.
Technical details
This vulnerability is a kernel panic (BUG) in the nilfs_copy_dirty_pages() function within the nilfs2 filesystem implementation. The root cause is a race condition where folio/page dirty flags can be cleared asynchronously after the filesystem detects metadata corruption and transitions to read-only mode. When nilfs_copy_dirty_pages() retrieves a folio that has lost its dirty status unexpectedly, it triggers a fatal kernel assertion. The fix changes the behavior to check if the filesystem is read-only and return an -EROFS error code instead of crashing, or issue a WARN_ONCE() warning if the filesystem is still writable. The vulnerability requires local access and affects kernels with the prior commit that introduced asynchronous dirty flag clearing after corruption detection.
Affected products
- Linux Linux kernel Multiple kernel versions (affected by prior commit, patched in 2026-07 onwards)
Timeline
- 2026-09-17: disclosed: CVE-2026-90418 published
- 2026-07-20: patched: Fix committed by Ryusuke Konishi
- 2026-09-14: patched: Fix merged to stable kernel tree by Greg Kroah-Hartman