Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2026-55392

Опубликовано: 18 июн. 2026
Источник: nvd
CVSS3: 5.5
EPSS Низкий

Описание

NILFS utilities through 2.3.0, fixed in commit 26efb5d, nilfs_sb_is_valid() function fails to validate s_log_block_size field in NILFS2 superblock before bit-shift operations. Attackers supplying crafted NILFS2 images trigger undefined behavior through oversized shifts or out-of-memory conditions, crashing tools like nilfs-tune and dumpseg.

EPSS

Процентиль: 5%
0.00151
Низкий

5.5 Medium

CVSS3

Дефекты

CWE-1284

Связанные уязвимости

CVSS3: 5.5
ubuntu
3 месяца назад

NILFS utilities through 2.3.0, fixed in commit 26efb5d, nilfs_sb_is_valid() function fails to validate s_log_block_size field in NILFS2 superblock before bit-shift operations. Attackers supplying crafted NILFS2 images trigger undefined behavior through oversized shifts or out-of-memory conditions, crashing tools like nilfs-tune and dumpseg.

CVSS3: 5.5
redhat
3 месяца назад

NILFS utilities through 2.3.0, fixed in commit 26efb5d, nilfs_sb_is_valid() function fails to validate s_log_block_size field in NILFS2 superblock before bit-shift operations. Attackers supplying crafted NILFS2 images trigger undefined behavior through oversized shifts or out-of-memory conditions, crashing tools like nilfs-tune and dumpseg.

CVSS3: 5.5
debian
3 месяца назад

NILFS utilities through 2.3.0, fixed in commit 26efb5d, nilfs_sb_is_va ...

suse-cvrf
3 месяца назад

Security update for nilfs-utils

CVSS3: 5.5
github
3 месяца назад

NILFS utilities through 2.3.0, fixed in commit 26efb5d, nilfs_sb_is_valid() function fails to validate s_log_block_size field in NILFS2 superblock before bit-shift operations. Attackers supplying crafted NILFS2 images trigger undefined behavior through oversized shifts or out-of-memory conditions, crashing tools like nilfs-tune and dumpseg.

EPSS

Процентиль: 5%
0.00151
Низкий

5.5 Medium

CVSS3

Дефекты

CWE-1284