CVE-2026-53320 Details
Description
In the Linux kernel, the following vulnerability has been resolved: nilfs2: reject zero bd_oblocknr in nilfs_ioctl_mark_blocks_dirty() nilfs_ioctl_mark_blocks_dirty() uses bd_oblocknr to detect dead blocks by comparing it with the current block number bd_blocknr. If they differ, the block is considered dead and skipped. However, bd_oblocknr should never be 0 since block 0 typically stores the primary superblock and is never a valid GC target block. A corrupted ioctl request with bd_oblocknr set to 0 causes the comparison to incorrectly match when the lookup returns -ENOENT and sets bd_blocknr to 0, bypassing the dead block check and calling nilfs_bmap_mark() on a non-existent block. This causes nilfs_btree_do_lookup() to return -ENOENT, triggering the WARN_ON(ret == -ENOENT). Fix this by rejecting ioctl requests with bd_oblocknr set to 0 at the beginning of each iteration. [ryusuke: slightly modified the commit message and comments for accuracy]
A vulnerability in the Linux kernel's nilfs2 file system has been addressed. The issue arose in the 'nilfs_ioctl_mark_blocks_dirty' function, which uses the 'bd_oblocknr' field to identify dead blocks by comparing it to the current block number, 'bd_blocknr'. If the numbers differ, the block is deemed dead and skipped. However, 'bd_oblocknr' should never be zero, as block zero usually contains the primary superblock and is not a valid target for garbage collection. A corrupted ioctl request with 'bd_oblocknr' set to zero disrupted this logic, allowing the function to incorrectly process a non-existent block, which triggered a warning. The vulnerability has been fixed by rejecting ioctl requests with 'bd_oblocknr' set to zero at the start of the function.
Users should update to the latest version of the Linux kernel where this vulnerability has been fixed.
Metrics
CVSS 4.0 Severity and Vector Strings:
No CVSS 4.0 data is available for this CVE.
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
No SSVC data is available for this CVE.
References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://git.kernel.org/stable/c/4525658002be3ad310b16bf8db48c8adb6a55d32 | kernel.org | Patch |
| https://git.kernel.org/stable/c/65e07964b4b2daf9a54e686cf0fa72d74a9648a8 | kernel.org | Patch |
| https://git.kernel.org/stable/c/94094e70fe292c9566502772d4d4d6d6a99204b1 | kernel.org | Patch |
| https://git.kernel.org/stable/c/9472d37799a0b9ff9b99639f35961ac2f0b3c9be | kernel.org | Patch |
| https://git.kernel.org/stable/c/b88f905d4449b70da6bda547be546e365e44352e | kernel.org | Patch |
| https://git.kernel.org/stable/c/be3e5d10643d3be1cbac9d9939f220a99253f980 | kernel.org | Patch |
| https://git.kernel.org/stable/c/e0a0c4903cbba351f0f5b5d104960d3a5b23202f | kernel.org | Patch |
| https://git.kernel.org/stable/c/e5ff0ba4b6983cdbcc826efc201e7179ece5d46f | kernel.org | Patch |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| NVD-CWE-noinfo | Insufficient Information to Classify Weakness | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| linux linux kernel | >= 2.6.30, < 5.10.258 >= 5.11, < 5.15.209 >= 5.16, < 6.1.175 >= 6.2, < 6.6.141 >= 6.7, < 6.12.91 >= 6.13, < 6.18.33 >= 6.19, < 7.0.10 |
CPE
Remediation
| |
Change History
2 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jul 6, 2026 | Initial Analysis | [email protected] |
| Jun 26, 2026 | New CVE Received | kernel.org |