Import Source
https://github.com/microsoft/AzureLinuxVulnerabilityData/blob/main/osv/AZL-90200.json
JSON Data
https://api.osv.dev/v1/vulns/AZL-90200
Upstream
Published
2026-06-18T19:16:23Z
Modified
2026-08-30T05:24:52Z
Summary
CVE-2026-55392 affecting package nilfs-utils 2.2.11-4
Details

NILFS utilities through 2.3.0, fixed in commit 26efb5d, nilfssbisvalid() function fails to validate slogblocksize field in NILFS2 superblock before bit-shift operations. Attackers supplying crafted NILFS2 images trigger undefined behavior through oversized shifts or out-of-memory conditions, crashing tools like nilfs-tune and dumpseg.

References

Affected packages

Azure Linux:3 / nilfs-utils

Package

Name
nilfs-utils
Purl
pkg:rpm/azure-linux/nilfs-utils

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Last affected
2.2.11-4

Database specific

source
"https://github.com/microsoft/AzureLinuxVulnerabilityData/blob/main/osv/AZL-90200.json"