Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-f559-vgh2-9hj6

Опубликовано: 18 июн. 2026
Источник: github
Github: Не прошло ревью
CVSS4: 6.7
CVSS3: 5.5

Описание

NILFS utilities through 2.3.0, fixed in commit 26efb5d, nilfs_sb_is_valid() function fails to validate s_log_block_size field in NILFS2 superblock before bit-shift operations. Attackers supplying crafted NILFS2 images trigger undefined behavior through oversized shifts or out-of-memory conditions, crashing tools like nilfs-tune and dumpseg.

NILFS utilities through 2.3.0, fixed in commit 26efb5d, nilfs_sb_is_valid() function fails to validate s_log_block_size field in NILFS2 superblock before bit-shift operations. Attackers supplying crafted NILFS2 images trigger undefined behavior through oversized shifts or out-of-memory conditions, crashing tools like nilfs-tune and dumpseg.

EPSS

Процентиль: 5%
0.00151
Низкий

6.7 Medium

CVSS4

5.5 Medium

CVSS3

Дефекты

CWE-1284

Связанные уязвимости

CVSS3: 5.5
ubuntu
около 2 месяцев назад

NILFS utilities through 2.3.0, fixed in commit 26efb5d, nilfs_sb_is_valid() function fails to validate s_log_block_size field in NILFS2 superblock before bit-shift operations. Attackers supplying crafted NILFS2 images trigger undefined behavior through oversized shifts or out-of-memory conditions, crashing tools like nilfs-tune and dumpseg.

CVSS3: 5.5
redhat
около 2 месяцев назад

NILFS utilities through 2.3.0, fixed in commit 26efb5d, nilfs_sb_is_valid() function fails to validate s_log_block_size field in NILFS2 superblock before bit-shift operations. Attackers supplying crafted NILFS2 images trigger undefined behavior through oversized shifts or out-of-memory conditions, crashing tools like nilfs-tune and dumpseg.

CVSS3: 5.5
nvd
около 2 месяцев назад

NILFS utilities through 2.3.0, fixed in commit 26efb5d, nilfs_sb_is_valid() function fails to validate s_log_block_size field in NILFS2 superblock before bit-shift operations. Attackers supplying crafted NILFS2 images trigger undefined behavior through oversized shifts or out-of-memory conditions, crashing tools like nilfs-tune and dumpseg.

CVSS3: 5.5
debian
около 2 месяцев назад

NILFS utilities through 2.3.0, fixed in commit 26efb5d, nilfs_sb_is_va ...

suse-cvrf
около 1 месяца назад

Security update for nilfs-utils

EPSS

Процентиль: 5%
0.00151
Низкий

6.7 Medium

CVSS4

5.5 Medium

CVSS3

Дефекты

CWE-1284