CVE-2026-64359: nilfs2: reject CLEAN_SEGMENTS ioctl with out-of-range segment numbers

Greg Kroah-Hartman <[email protected]> Sat, 25 Jul 2026 10:49:36 +0200
Newsgroups org.kernel.vger.linux-cve-announce
Message-ID <2026072520-CVE-2026-64359-1649@gregkh>
From: Greg Kroah-Hartman <[email protected]>

Description
===========

In the Linux kernel, the following vulnerability has been resolved:

nilfs2: reject CLEAN_SEGMENTS ioctl with out-of-range segment numbers

Syzbot reported a hung task in nilfs_transaction_begin() where multiple
tasks performing chmod() on a nilfs2 mount blocked for over 143 seconds
waiting to acquire ns_segctor_sem for read:

  INFO: task syz.0.17:5918 blocked for more than 143 seconds.
  Call Trace:
   schedule+0x164/0x360
   rwsem_down_read_slowpath+0x6d9/0x940
   down_read+0x99/0x2e0
   nilfs_transaction_begin+0x364/0x710 fs/nilfs2/segment.c:221
   nilfs_setattr+0x124/0x2c0 fs/nilfs2/inode.c:921
   notify_change+0xc1a/0xf40
   chmod_common+0x273/0x4a0
   do_fchmodat+0x12d/0x230

The writer holding ns_segctor_sem was a concurrent
NILFS_IOCTL_CLEAN_SEGMENTS caller, stuck inside printk while emitting
per-element warnings from nilfs_sufile_updatev():

   __nilfs_msg+0x373/0x450 fs/nilfs2/super.c:78
   nilfs_sufile_updatev+0x21c/0x6d0 fs/nilfs2/sufile.c:186
   nilfs_sufile_freev fs/nilfs2/sufile.h:93 [inline]
   nilfs_free_segments fs/nilfs2/segment.c:1140 [inline]
   nilfs_segctor_collect_blocks fs/nilfs2/segment.c:1261 [inline]
   nilfs_segctor_do_construct+0x1f55/0x76c0
   nilfs_clean_segments+0x3bd/0xa50
   nilfs_ioctl_clean_segments fs/nilfs2/ioctl.c:922 [inline]
   nilfs_ioctl+0x261f/0x2780

The root cause is that user-supplied segment numbers are not validated
before nilfs_clean_segments() begins doing work; the range check on
each segnum is performed deep inside the call chain by
nilfs_sufile_updatev(), which emits a nilfs_warn() per invalid entry
while still holding the segctor lock and the sufile mi_sem.  Under load
(repeated invocations across multiple mounts saturating the global
printk path), the cumulative printk latency keeps ns_segctor_sem held
long enough to trip the hung_task watchdog, blocking concurrent
operations such as chmod() that need ns_segctor_sem for read.

Fix by validating the contents of kbufs[4] in nilfs_clean_segments()
immediately after acquiring ns_segctor_sem via nilfs_transaction_lock().
Holding ns_segctor_sem serializes the check against
nilfs_ioctl_resize(), which can modify ns_nsegments, so the validation
uses a consistent value.  Out-of-range segment numbers are rejected
with -EINVAL before any segment-cleaning work begins, so the bad
entries never reach the per-element diagnostic path inside
nilfs_sufile_updatev().

The Linux kernel CVE team has assigned CVE-2026-64359 to this issue.


Affected and fixed versions
===========================

	Issue introduced in 2.6.31 with commit 071cb4b81987a28c7ac2702003cff3e61684a630 and fixed in 5.10.261 with commit 3ed388ec3b8922383d1e2d4432d7bd4cbbf8364e
	Issue introduced in 2.6.31 with commit 071cb4b81987a28c7ac2702003cff3e61684a630 and fixed in 5.15.212 with commit 876c98e0fc65f071680c03c2e2ee3ef7ff9ca078
	Issue introduced in 2.6.31 with commit 071cb4b81987a28c7ac2702003cff3e61684a630 and fixed in 6.1.178 with commit 39607452b1400c7bf748f15122df4d058b768c5b
	Issue introduced in 2.6.31 with commit 071cb4b81987a28c7ac2702003cff3e61684a630 and fixed in 6.6.145 with commit 286f77d002a337735c0846d7480a82d9cda2aa31
	Issue introduced in 2.6.31 with commit 071cb4b81987a28c7ac2702003cff3e61684a630 and fixed in 6.12.96 with commit 0789f0a6710713254a08f3a7d2ecbb6d1cbcf0aa
	Issue introduced in 2.6.31 with commit 071cb4b81987a28c7ac2702003cff3e61684a630 and fixed in 6.18.39 with commit 223463c488b0554212a94de971ea538eb2805fc7
	Issue introduced in 2.6.31 with commit 071cb4b81987a28c7ac2702003cff3e61684a630 and fixed in 7.1.4 with commit d26aef771b4f6923da9f89d6d5b70d8def5853de
	Issue introduced in 2.6.31 with commit 071cb4b81987a28c7ac2702003cff3e61684a630 and fixed in 7.2-rc1 with commit 0e7a690fe435f8d5ea3feb7c1d8d73ba7e8b8aa9

Please see https://www.kernel.org for a full list of currently supported
kernel versions by the kernel community.

Unaffected versions might change over time as fixes are backported to
older supported kernel versions.  The official CVE entry at
	https://cve.org/CVERecord/?id=CVE-2026-64359
will be updated if fixes are backported, please check that for the most
up to date information about this issue.


Affected files
==============

The file(s) affected by this issue are:
	fs/nilfs2/segment.c


Mitigation
==========

The Linux kernel CVE team recommends that you update to the latest
stable kernel version for this, and many other bugfixes.  Individual
changes are never tested alone, but rather are part of a larger kernel
release.  Cherry-picking individual commits is not recommended or
supported by the Linux kernel community at all.  If however, updating to
the latest release is impossible, the individual changes to resolve this
issue can be found at these commits:
	https://git.kernel.org/stable/c/3ed388ec3b8922383d1e2d4432d7bd4cbbf8364e
	https://git.kernel.org/stable/c/876c98e0fc65f071680c03c2e2ee3ef7ff9ca078
	https://git.kernel.org/stable/c/39607452b1400c7bf748f15122df4d058b768c5b
	https://git.kernel.org/stable/c/286f77d002a337735c0846d7480a82d9cda2aa31
	https://git.kernel.org/stable/c/0789f0a6710713254a08f3a7d2ecbb6d1cbcf0aa
	https://git.kernel.org/stable/c/223463c488b0554212a94de971ea538eb2805fc7
	https://git.kernel.org/stable/c/d26aef771b4f6923da9f89d6d5b70d8def5853de
	https://git.kernel.org/stable/c/0e7a690fe435f8d5ea3feb7c1d8d73ba7e8b8aa9