CVE-2026-64359
Awaiting Analysis Awaiting Analysis - Queue

nilfs2 Kernel Hung Task Due to Unvalidated CLEAN_SEGMENTS Segment Numbers

Vulnerability report for CVE-2026-64359, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-07-25

Last updated on: 2026-08-11

Assigner: kernel.org

Description

In the Linux kernel, the following vulnerability has been resolved: nilfs2: reject CLEAN_SEGMENTS ioctl with out-of-range segment numbers Syzbot reported a hung task in nilfs_transaction_begin() where multiple tasks performing chmod() on a nilfs2 mount blocked for over 143 seconds waiting to acquire ns_segctor_sem for read: INFO: task syz.0.17:5918 blocked for more than 143 seconds. Call Trace: schedule+0x164/0x360 rwsem_down_read_slowpath+0x6d9/0x940 down_read+0x99/0x2e0 nilfs_transaction_begin+0x364/0x710 fs/nilfs2/segment.c:221 nilfs_setattr+0x124/0x2c0 fs/nilfs2/inode.c:921 notify_change+0xc1a/0xf40 chmod_common+0x273/0x4a0 do_fchmodat+0x12d/0x230 The writer holding ns_segctor_sem was a concurrent NILFS_IOCTL_CLEAN_SEGMENTS caller, stuck inside printk while emitting per-element warnings from nilfs_sufile_updatev(): __nilfs_msg+0x373/0x450 fs/nilfs2/super.c:78 nilfs_sufile_updatev+0x21c/0x6d0 fs/nilfs2/sufile.c:186 nilfs_sufile_freev fs/nilfs2/sufile.h:93 [inline] nilfs_free_segments fs/nilfs2/segment.c:1140 [inline] nilfs_segctor_collect_blocks fs/nilfs2/segment.c:1261 [inline] nilfs_segctor_do_construct+0x1f55/0x76c0 nilfs_clean_segments+0x3bd/0xa50 nilfs_ioctl_clean_segments fs/nilfs2/ioctl.c:922 [inline] nilfs_ioctl+0x261f/0x2780 The root cause is that user-supplied segment numbers are not validated before nilfs_clean_segments() begins doing work; the range check on each segnum is performed deep inside the call chain by nilfs_sufile_updatev(), which emits a nilfs_warn() per invalid entry while still holding the segctor lock and the sufile mi_sem. Under load (repeated invocations across multiple mounts saturating the global printk path), the cumulative printk latency keeps ns_segctor_sem held long enough to trip the hung_task watchdog, blocking concurrent operations such as chmod() that need ns_segctor_sem for read. Fix by validating the contents of kbufs[4] in nilfs_clean_segments() immediately after acquiring ns_segctor_sem via nilfs_transaction_lock(). Holding ns_segctor_sem serializes the check against nilfs_ioctl_resize(), which can modify ns_nsegments, so the validation uses a consistent value. Out-of-range segment numbers are rejected with -EINVAL before any segment-cleaning work begins, so the bad entries never reach the per-element diagnostic path inside nilfs_sufile_updatev().

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-07-25
Last Modified
2026-08-11
Generated
2026-08-14
AI Q&A
2026-07-25
EPSS Evaluated
2026-08-13
NVD
EUVD

Affected Vendors & Products

Currently, no data is known.

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-UNKNOWN

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability in the Linux kernel's nilfs2 filesystem allows a user to cause a system hang by providing out-of-range segment numbers to the CLEAN_SEGMENTS ioctl. The issue occurs because the kernel does not validate these segment numbers before processing them, leading to a deadlock when multiple operations try to access the filesystem simultaneously.

Detection Guidance

This vulnerability affects the nilfs2 filesystem in the Linux kernel. To detect it, check if your system is running a vulnerable kernel version. Use 'uname -r' to see the kernel version. If you are running a kernel before the fix, the vulnerability may be present. Monitor system logs for hung tasks or warnings related to nilfs2 operations, especially during chmod or ioctl calls.

Impact Analysis

An attacker could exploit this to cause a denial-of-service condition, making the system unresponsive for over 143 seconds. This could disrupt critical services relying on the nilfs2 filesystem, such as file operations or storage management.

Compliance Impact

This vulnerability does not directly affect compliance with GDPR, HIPAA, or similar standards as it is a Linux kernel-specific issue related to filesystem operations and task blocking. Compliance impacts would only occur if the vulnerability led to data corruption, unauthorized access, or denial of service in systems handling regulated data.

Mitigation Strategies

Immediately update your Linux kernel to the latest patched version that includes the fix for this vulnerability. If updating is not immediately possible, avoid using nilfs2 filesystems or restrict access to them. Monitor system performance and logs for hung tasks or warnings related to nilfs2 operations.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-64359. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart