Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

CVE-2026-90420— nilfs2: fix infinite loop in nilfs_clean_segments()

Quick assessment

Affected
Linux Linux
Exploitation
No confirmed in-the-wild exploitation; assess based on exposure
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

以下是该漏洞描述信息的中文翻译: 在 Linux 内核中,已修复如下漏洞: nilfs2:修复 nilfs_clean_segments() 中的无限循环问题 syzbot 报告了发生在 nilfs_transaction_begin() 中的任务挂起问题。该问题发生的原因是,当 nilfs_segctor_construct() 反复返回 -EROFS(例如,在 I/O 错误后将设备以只读方式重新挂载)时,清理程序 ioctl 会陷入无限循环。 当前在 nilfs_clean_segments() 中,如果 er

AI Predicted 7.5 Difficulty: Moderate EPSS 0.22% · P11

Affected Version Matrix 18

VendorProduct Version RangeStatus
Linux Linux 9ff05123e3bfbb1d2b68ba1d9bf1f7d1dffc1453< e3e9367dae1a6392cbb14ab0b2ab5edbf39735c3 affected
9ff05123e3bfbb1d2b68ba1d9bf1f7d1dffc1453< 217b967ad7887a3e1ebc08f46f6484e081acd4b4 affected
9ff05123e3bfbb1d2b68ba1d9bf1f7d1dffc1453< 3bcdbdaac884a4baa59716cf9bd9470c75276e2d affected
9ff05123e3bfbb1d2b68ba1d9bf1f7d1dffc1453< d7afca8e4efbf4c455b4663c29ae59fde2f1b671 affected
9ff05123e3bfbb1d2b68ba1d9bf1f7d1dffc1453< c07e5ad6539e7e9350d5c65cbf8adb69d1711b15 affected
9ff05123e3bfbb1d2b68ba1d9bf1f7d1dffc1453< 1fc6df85b4954b6fda9c351843aaca3c06f66d8d affected
9ff05123e3bfbb1d2b68ba1d9bf1f7d1dffc1453< 8cea0bc78ac64cb88da49c07f80bf2cf9fb7aff8 affected
9ff05123e3bfbb1d2b68ba1d9bf1f7d1dffc1453< ce5a5ad1a8330a2fcfdd9ec2ab341be739e89a18 affected
… +10 more rows
Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2026-90420

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
nilfs2: fix infinite loop in nilfs_clean_segments()
Source: CVE Program / CVE List V5
Vulnerability Description
In the Linux kernel, the following vulnerability has been resolved: nilfs2: fix infinite loop in nilfs_clean_segments() syzbot reported a hung task in nilfs_transaction_begin(). This occurs because the cleaner ioctl falls into an infinite loop if nilfs_segctor_construct() repeatedly returns -EROFS (e.g. the device is remounted as read-only after an I/O error). Currently in nilfs_clean_segments(), if err is non-zero, it logs the error and sleeps but doesn't abort when it encounters a terminal error like -EROFS. This causes the thread to loop forever. Fix this by breaking out of the loop if nilfs_segctor_construct() returns -EROFS. This matches the behaviour in nilfs_segctor_write_out(), which also handles -EROFS.
Source: CVE Program / CVE List V5
CVSS Information
N/A
Source: CVE Program / CVE List V5
Vulnerability Type
N/A
Source: CVE Program / CVE List V5

Affected Products

Vendor Product Affected Versions CPE Subscribe
Linux Linux 9ff05123e3bfbb1d2b68ba1d9bf1f7d1dffc1453 ~ e3e9367dae1a6392cbb14ab0b2ab5edbf39735c3 -
Linux Linux 2.6.30 -

II. Public POCs for CVE-2026-90420

# POC Description Source Link Shenlong Link
AI-Generated POC Premium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2026-90420

请登录查看更多情报信息。

Patches & Fixes for CVE-2026-90420 (8)

Same Patch Batch · Linux · 2026-09-17 · 600 CVEs total

CVE-2026-92489 9.8 CRITICAL xfrm: Fix skb double-free in xfrm_dev_direct_output()
CVE-2026-90235 9.8 CRITICAL sunrpc: xprtsock: annotate shared socket callbacks with READ_ONCE/WRITE_ONCE
CVE-2026-90173 9.8 CRITICAL smb: smbdirect: free completion queues with ib_free_cq()
CVE-2026-90104 9.8 CRITICAL NFSv4.1: zero referring call lists before decoding
CVE-2026-90151 9.8 CRITICAL NFSv4: remove callback IDR entry on client allocation failure
CVE-2026-90110 9.4 CRITICAL inetpeer: randomize RB-tree node comparison using SipHash
CVE-2026-90230 9.1 CRITICAL nvmet: fix heap out-of-bounds read in nvmet_auth_negotiate()
CVE-2026-90414 9.1 CRITICAL IB/isert: reject PDUs declaring more data than was received
CVE-2026-90413 9.1 CRITICAL IB/isert: reject login PDUs declaring more data than was received
CVE-2026-90367 8.8 HIGH wifi: mt76: mt7996: hold dev->mt76.mutex while disabling tx worker in SER
CVE-2026-90329 8.8 HIGH HID: synchronize input before cleaning up a failed probe
CVE-2026-93189 8.8 HIGH HID: core: quiesce input in hid_hw_stop() to prevent use-after-free
CVE-2026-90240 8.8 HIGH iommu/vt-d: Flush context cache with correct SID when tearing down aliases
CVE-2026-90357 8.8 HIGH wifi: mt76: mt7915: unlink TWT flow if the MCU rejects the agreement
CVE-2026-90286 8.8 HIGH drm/amdgpu/gfx6: Use PFP on the compute queues too
CVE-2026-93042 8.8 HIGH dmaengine: dw-edma: Terminate all descriptors without callbacks
CVE-2026-90256 8.8 HIGH Bluetooth: L2CAP: use proto_lock for l2cap_data to fix l2cap_disconn_ind
CVE-2026-90380 8.8 HIGH wifi: mt76: mt792x: fix use-after-free in mt76_rx_poll_complete
CVE-2026-90381 8.8 HIGH wifi: mt76: fix handling channel context with different bands in mt76_switch_vif_chanctx()
CVE-2026-90425 8.8 HIGH iommu/tegra241-cmdqv: Require exactly one Stream ID for a vSID

Showing top 20 of 600 CVEs. View all on vendor page &rarr; →

IV. Related Vulnerabilities

V. Comments for CVE-2026-90420

No comments yet


Leave a comment