CVE-2026-55392
Description
NILFS utilities through 2.3.0, fixed in commit 26efb5d, nilfs_sb_is_valid() function fails to validate s_log_block_size field in NILFS2 superblock before bit-shift operations. Attackers supplying crafted NILFS2 images trigger undefined behavior through oversized shifts or out-of-memory conditions, crashing tools like nilfs-tune and dumpseg.
How to fix CVE-2026-55392
No fixed version has been published yet. Mitigate by removing the affected package or applying upstream guidance from the references below.
- Debian/nilfs-tools—no fix listed
Is CVE-2026-55392 being exploited?
No exploitation signal available. Neither CISA KEV nor a current EPSS score has been published for CVE-2026-55392.
Affected packages (1)
- from 0