CVE-2026-53320
Description
A flaw was found in the Linux kernel's nilfs2 filesystem. A local attacker could exploit this vulnerability by sending a specially crafted input/output control (ioctl) request to the nilfs_ioctl_mark_blocks_dirty() function. By providing a zero block number, the attacker can bypass a critical dead block check, causing the system to attempt operations on a non-existent block. This ultimately leads to a system crash, resulting in a Denial of Service (DoS).
Understanding the Weakness (CWE)
Integrity,Confidentiality,Availability
Technical Impact: Modify Application Data; Execute Unauthorized Code or Commands
An attacker could modify the structure of the message or data being sent to the downstream component, possibly injecting commands.
Availability
Technical Impact: DoS: Resource Consumption (Other)
in some contexts, a negative value could lead to resource consumption.
Confidentiality,Integrity
Technical Impact: Modify Memory; Read Memory
If a negative value is used to access memory, buffers, or other indexable structures, it could access memory outside the bounds of the buffer.
Frequently Asked Questions
Not sure what something means? Check out our Security Glossary.
Want to get errata notifications? Sign up here.