Junglewise Threat Intelligence

CVE-2026-90419: Linux kernel nilfs2 out-of-bounds read in super root block parsing

CVE-2026-90419 · Severity: high · CVSS 7.1 · Published 2026-09-17

Technologies: Linux Kernel. Vendors: Linux.

Executive brief

The Linux kernel's nilfs2 filesystem driver contains an out-of-bounds read vulnerability when parsing malformed filesystem images. An attacker with access to craft a malicious filesystem image could trigger the kernel to read beyond allocated memory boundaries in the super-root block handler, potentially causing a kernel crash or information disclosure.

Technical details

The vulnerability exists in the nilfs2 filesystem driver's super-root inode metadata parsing logic. The driver failed to validate that the computed on-disk footprint of a super-root inode's metadata does not exceed the filesystem block size before passing it to nilfs_read_inode_common(). An attacker can supply a malformed filesystem image with an oversized inode size value that causes the read operation to exceed the super-root block's allocated memory. The fix validates that NILFS_SR_BYTES(inode_size) does not exceed ns_blocksize and rejects such configurations with -EINVAL. Exploitation requires the ability to mount or provide a crafted filesystem image; local user interaction is needed. A patch is available in the Linux kernel stable tree.

Affected products

  • Linux Linux kernel multiple versions prior to patch (commit 7cb2f76a6a2ba2130b577cb8ac13e1e46c4fc689 and later)

Timeline

  • 2026-09-17: disclosed: CVE-2026-90419 published
  • 2026-09-14: patched: Patch committed to stable kernel tree by Greg Kroah-Hartman

References

Related threats