CVE-2026-55392: Nilfs-Dev Nilfs-Utils

Medium severity, CVSS 5.5. EPSS: 0.2% chance of exploitation in the next 30 days.

NILFS utilities through 2.3.0, fixed in commit 26efb5d, nilfs_sb_is_valid() function fails to validate s_log_block_size field in NILFS2 superblock before bit-shift operations. Attackers supplying crafted NILFS2 images trigger undefined behavior through oversized shifts or out-of-memory conditions, crashing tools like nilfs-tune and dumpseg.

Affected products

  • Nilfs-Dev Nilfs-Utils: up to and including 2.3.0

Published 2026-06-18. Last modified 2026-07-14.