From mboxrd@z Thu Jan 1 00:00:00 1970 Received: from smtp.kernel.org (aws-us-west-2-korg-mail-alma10-1.taild15c8.ts.net [100.103.45.18]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id 41FD74A1E03 for ; Fri, 4 Sep 2026 15:18:13 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=100.103.45.18 ARC-Seal:i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1788535094; cv=none; b=enKpg1DdWFf+0PBadzZArDeBFJ/y2ldYeSlbHKqIVAnjqbxUqmQSsrJyZMcunZTNTcZLfNDb1fmh9aUkrb79gEBfvGh9RvjD5bXIp9WdUXcm2uiWXK9Xia6NB0l5ccEpbdnsRVn4Zw4Fhz7HRZvRkhY13kln6WLW419TSP9XPMI= ARC-Message-Signature:i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1788535094; c=relaxed/simple; bh=m8b8U49R4VDcANPMDbhWi/mCVoLBPDpLirxWr7YI1g4=; h=From:To:Cc:Subject:Date:Message-ID:MIME-Version; b=dCrrtizzH2uJQeywDcRuTsGZxK1CanTKkCo0fACDZG7pJ2rBfCVqOmhkV170A84eAWwyGRxDxIeXC/SHwf5dA9Dxt14cZ7rqoxZHVQXTaFH3WpOHrVOAKwA6hJKPgrcoAlLn++HrFB2EAemyVh8bPgrlxEqc2qpzbkPVLI2SGlk= ARC-Authentication-Results:i=1; smtp.subspace.kernel.org; dkim=pass (1024-bit key) header.d=linuxfoundation.org header.i=@linuxfoundation.org header.b=r30EBjGL; arc=none smtp.client-ip=100.103.45.18 Authentication-Results: smtp.subspace.kernel.org; dkim=pass (1024-bit key) header.d=linuxfoundation.org header.i=@linuxfoundation.org header.b="r30EBjGL" Received: by smtp.kernel.org (Postfix) with ESMTPSA id 62C8A1F00A3D; Fri, 4 Sep 2026 15:18:12 +0000 (UTC) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=linuxfoundation.org; s=korg; t=1788535093; bh=GCTMOqkZn/swFXvFXheR90Fojo9Ms6r9vRViBfXrZzI=; h=From:To:Cc:Subject:Date:Reply-To; b=r30EBjGLEPtzNLyRd0gPNQ2NYkuPt5HeKqhJ5YRgxNzdjj0f5rQtNfoOeddI3mTAC DbyJSLvg2Hwc0u8JCwmy08CQ0E2Hxv25TmQgxri/tg8ApfS0iMpWwlogPL7/t0Bihe J4kiEu918oYstl+Y39ADUjXG+5ht8GS+yqCunNGY= From: Greg Kroah-Hartman To: linux-cve-announce@vger.kernel.org Cc: Greg Kroah-Hartman Subject: CVE-2026-80807: nilfs2: reject invalid block index in GC ioctl Date: Fri, 4 Sep 2026 17:11:46 +0200 Message-ID: <2026090410-CVE-2026-80807-6993@gregkh> X-Mailer: git-send-email 2.55.0 Reply-To: , Precedence: bulk X-Mailing-List: linux-cve-announce@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 X-Developer-Signature: v=1; a=openpgp-sha256; l=4674; i=gregkh@linuxfoundation.org; h=from:subject:message-id; bh=Ov5YCh/6KPuHizWmI5MjM1W1l2hiveR7VPWze0KXnzU=; b=owGbwMvMwCRo6H6F97bub03G02pJDFmz7veVOO8O+Dw5NKAzIe9GocK3J0rFF9t3NEoWTDjPp Fl8wkWxI5aFQZCJQVZMkeXLNp6j+ysOKXoZ2p6GmcPKBDKEgYtTACayeRPD/PK22XUzOFu8WLsU Z/evlT2usOm3DcOChVN11pX/kQ3v/spkzpeysVPixUZ9AA== X-Developer-Key: i=gregkh@linuxfoundation.org; a=openpgp; fpr=F4B60CC5BF78C2214A313DCB3147D40DDB2DFB29 Content-Transfer-Encoding: 8bit From: Greg Kroah-Hartman Description =========== In the Linux kernel, the following vulnerability has been resolved: nilfs2: reject invalid block index in GC ioctl Syzbot reported list corruption caused by a double list_add_tail() call on bh->b_assoc_buffers within nilfs_lookup_dirty_data_buffers(). Analysis revealed that the root cause was the insertion of a page/folio with a page index of ULONG_MAX into the page cache via the GC ioctl. filemap_get_folios_tag(), called by nilfs_lookup_dirty_data_buffers(), repeatedly detects a dirty folio with a page index of ULONG_MAX due to index wrap-around, leading to duplicate processing of dirty buffers. As a preparatory step, the GC ioctl loads the page/folio of the block to be moved during GC and inserts it into the page cache based on information in the nilfs_vdesc structure passed as an argument. Normally, this does not cause issues because the user-space GC library configures the nilfs_vdesc structure properly. However, since there is no range check on the parameters determining the page index, a request with artificially crafted parameters -- such as those generated by Syzbot -- can result in a page/folio being inserted with a page index of ULONG_MAX, triggering the above problem. This resolves the issue by checking the ranges of 'vd_offset' and 'vd_vblocknr' in the nilfs_vdesc structure that determine the page index, thereby preventing the invalid page/folio insertions. The Linux kernel CVE team has assigned CVE-2026-80807 to this issue. Affected and fixed versions =========================== Issue introduced in 2.6.30 with commit 7942b919f7321f95a777d396ff7894a7a83dc9b0 and fixed in 5.10.269 with commit 898404cdf882d7b54f1132f75570984ca3214796 Issue introduced in 2.6.30 with commit 7942b919f7321f95a777d396ff7894a7a83dc9b0 and fixed in 5.15.220 with commit ba8a8b563a28d358c45c62a306d421434a058648 Issue introduced in 2.6.30 with commit 7942b919f7321f95a777d396ff7894a7a83dc9b0 and fixed in 6.1.187 with commit 3bd064ccc70b85f9a3d53aece29dc8473be5a226 Issue introduced in 2.6.30 with commit 7942b919f7321f95a777d396ff7894a7a83dc9b0 and fixed in 6.6.156 with commit a5e776e2937581d67ec5b9b4d27b0f70d7baa6b1 Issue introduced in 2.6.30 with commit 7942b919f7321f95a777d396ff7894a7a83dc9b0 and fixed in 6.12.108 with commit 68aa9ab6f8f2895713aa6ddf781463ed8ea5ba44 Issue introduced in 2.6.30 with commit 7942b919f7321f95a777d396ff7894a7a83dc9b0 and fixed in 6.18.47 with commit e447f7edb99bd00cec63d6f3049e2e5074946f71 Issue introduced in 2.6.30 with commit 7942b919f7321f95a777d396ff7894a7a83dc9b0 and fixed in 7.1.11 with commit ec6ddf271dfa4c7e3147bc2c8b2bad4315f316a1 Issue introduced in 2.6.30 with commit 7942b919f7321f95a777d396ff7894a7a83dc9b0 and fixed in 7.2.1 with commit fbcfb75c20d71a5b542ad4ac3b79d10b997c8152 Issue introduced in 2.6.30 with commit 7942b919f7321f95a777d396ff7894a7a83dc9b0 and fixed in 7.3-rc1 with commit a1735eae55448bc79c2da6593455791e886f6ed8 Please see https://www.kernel.org for a full list of currently supported kernel versions by the kernel community. Unaffected versions might change over time as fixes are backported to older supported kernel versions. The official CVE entry at https://cve.org/CVERecord/?id=CVE-2026-80807 will be updated if fixes are backported, please check that for the most up to date information about this issue. Affected files ============== The file(s) affected by this issue are: fs/nilfs2/ioctl.c Mitigation ========== The Linux kernel CVE team recommends that you update to the latest stable kernel version for this, and many other bugfixes. Individual changes are never tested alone, but rather are part of a larger kernel release. Cherry-picking individual commits is not recommended or supported by the Linux kernel community at all. If however, updating to the latest release is impossible, the individual changes to resolve this issue can be found at these commits: https://git.kernel.org/stable/c/898404cdf882d7b54f1132f75570984ca3214796 https://git.kernel.org/stable/c/ba8a8b563a28d358c45c62a306d421434a058648 https://git.kernel.org/stable/c/3bd064ccc70b85f9a3d53aece29dc8473be5a226 https://git.kernel.org/stable/c/a5e776e2937581d67ec5b9b4d27b0f70d7baa6b1 https://git.kernel.org/stable/c/68aa9ab6f8f2895713aa6ddf781463ed8ea5ba44 https://git.kernel.org/stable/c/e447f7edb99bd00cec63d6f3049e2e5074946f71 https://git.kernel.org/stable/c/ec6ddf271dfa4c7e3147bc2c8b2bad4315f316a1 https://git.kernel.org/stable/c/fbcfb75c20d71a5b542ad4ac3b79d10b997c8152 https://git.kernel.org/stable/c/a1735eae55448bc79c2da6593455791e886f6ed8