CVE-2026-55392: Nilfs-Dev Nilfs-Utils
Medium severity, CVSS 5.5. EPSS: 0.2% chance of exploitation in the next 30 days.
NILFS utilities through 2.3.0, fixed in commit 26efb5d, nilfs_sb_is_valid() function fails to validate s_log_block_size field in NILFS2 superblock before bit-shift operations. Attackers supplying crafted NILFS2 images trigger undefined behavior through oversized shifts or out-of-memory conditions, crashing tools like nilfs-tune and dumpseg.
Affected products
- Nilfs-Dev Nilfs-Utils: up to and including 2.3.0
Published 2026-06-18. Last modified 2026-07-14.