CVE-2026-89723

Summary

In the Linux kernel, the following vulnerability has been resolved:

nilfs2: fix slab-out-of-bounds in nilfs_direct_propagate after truncation

Shuangpeng Bai reported that KASAN detected a slab-out-of-bounds error in nilfs_direct_propagate() during testing.

Analysis revealed that after truncating a file, a node block immediately below the B-tree root was not deleted. Instead, it remained in the B-tree node cache in a dirty state. The log writer subsequently detected this block and incorrectly invoked nilfs_direct_propagate() on it, which is designed to handle only data blocks in direct mapping.

B-tree nodes in the cache are managed by virtual block numbers, and their logical keys typically exceed the range expected by direct mapping. Consequently, processing such a node as a direct mapping entry triggers a slab-out-of-bounds access.

The root cause is that when a B-tree mapping collapses into a direct mapping during truncation, an intermediate node block pointed to by the root node is left behind as garbage instead of being explicitly deleted.

This resolves the issue by adding a nilfs_btree_discard() operation to delete the remaining intermediate node block during the conversion. A 'deform' flag is added to the bop_delete interface to explicitly signal that the deletion is part of a mapping transformation. This allows the B-tree mapping implementation to perform the necessary cleanup and discarding of the residual node structure that would be otherwise be left orphaned after the transition.

Affected Software

VendorProductVersion RangeStatus
LinuxLinux36a580eb489f54d81a0534974962e732a314b999 < 5d3783c451a546373662ee11ec17019273e68034affected
LinuxLinux36a580eb489f54d81a0534974962e732a314b999 < 448636c745a3f3b8582a0b8ce718c890a11c0fa9affected
LinuxLinux36a580eb489f54d81a0534974962e732a314b999 < 28362e8ce51377afdec1782e661e808328a10514affected
LinuxLinux36a580eb489f54d81a0534974962e732a314b999 < 45662dedb8f272ef7f16e69f13424c4bd0399240affected
LinuxLinux2.6.30affected
LinuxLinux0 < 2.6.30unaffected
LinuxLinux6.12.109 <= 6.12.*unaffected
LinuxLinux6.18.50 <= 6.18.*unaffected
LinuxLinux7.2.4 <= 7.2.*unaffected
LinuxLinux7.3-rc1 <= *unaffected

Weaknesses

References