VYPR
Unrated severityNVD Advisory· Published Sep 17, 2026

CVE-2026-90419

CVE-2026-90419

Description

In the Linux kernel, the following vulnerability has been resolved:

nilfs2: prevent out-of-bounds read in super root block parsing

super-root inode metadata size is trusted before nilfs_read_inode_common().

Reject super-root inode sizes whose computed on-disk footprint exceeds the filesystem block size. This prevents malformed filesystem images from making nilfs_read_inode_common() read past the end of the super-root block.

[ryusuke: clarify the commit title]

Affected products

2

Patches

Vulnerability mechanics

References

8

News mentions

0

No linked articles in our index yet.