NILFS utilities through 2.3.0, fixed in commit 26efb5d, nilfssbisvalid() function fails to validate slogblocksize field in NILFS2 superblock before bit-shift operations. Attackers supplying crafted NILFS2 images trigger undefined behavior through oversized shifts or out-of-memory conditions, crashing tools like nilfs-tune and dumpseg.
{
"cwe_ids": [
"CWE-1284"
],
"osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/55xxx/CVE-2026-55392.json",
"cna_assigner": "VulnCheck"
}"2026-07-22T03:29:46Z"
[
{
"signature_type": "Line",
"target": {
"file": "lib/sb.c"
},
"deprecated": false,
"source": "https://github.com/nilfs-dev/nilfs-utils/commit/26efb5daff0757365101035145331b0a5a85d9d9",
"id": "CVE-2026-55392-29dcb09f",
"signature_version": "v1",
"digest": {
"line_hashes": [
"139429108555604321755893781337324730698",
"290071847760145223543359583221887599697",
"248067144152988933005337506338606647165",
"236176387179303495011254244390291711421"
],
"threshold": 0.9
}
},
{
"signature_type": "Function",
"target": {
"file": "lib/sb.c",
"function": "nilfs_sb_is_valid"
},
"deprecated": false,
"source": "https://github.com/nilfs-dev/nilfs-utils/commit/26efb5daff0757365101035145331b0a5a85d9d9",
"id": "CVE-2026-55392-2a8dffb0",
"signature_version": "v1",
"digest": {
"function_hash": "176752800563585648743943259965792844133",
"length": 316.0
}
}
]
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-55392.json"