Описание
Security update for nilfs-utils
This update for nilfs-utils fixes the following issues:
Changes in nilfs-utils:
- CVE-2026-55392: Fixed undefined behavior in nilfs_sb_is_valid() (bsc#1268553)
Список пакетов
openSUSE Leap 16.0
libnilfs0-2.2.9-bp160.2.1
libnilfscleaner0-2.2.9-bp160.2.1
libnilfsgc0-2.2.9-bp160.2.1
nilfs-utils-2.2.9-bp160.2.1
nilfs-utils-devel-2.2.9-bp160.2.1
Ссылки
- SUSE Security Ratings
- SUSE Bug 1268553
- SUSE CVE CVE-2026-55392 page
Описание
NILFS utilities through 2.3.0, fixed in commit 26efb5d, nilfs_sb_is_valid() function fails to validate s_log_block_size field in NILFS2 superblock before bit-shift operations. Attackers supplying crafted NILFS2 images trigger undefined behavior through oversized shifts or out-of-memory conditions, crashing tools like nilfs-tune and dumpseg.
Затронутые продукты
openSUSE Leap 16.0:libnilfs0-2.2.9-bp160.2.1
openSUSE Leap 16.0:libnilfscleaner0-2.2.9-bp160.2.1
openSUSE Leap 16.0:libnilfsgc0-2.2.9-bp160.2.1
openSUSE Leap 16.0:nilfs-utils-2.2.9-bp160.2.1
Ссылки
- CVE-2026-55392
- SUSE Bug 1268553