{"id":"CVE-2026-89723","title":"kernel: nilfs2: fix slab-out-of-bounds in nilfs_direct_propagate after truncation (CVE-2026-89723)","summary":"A flaw was found in the nilfs2 file system component of the Linux kernel. When a file is truncated, an intermediate node block is not properly deleted and remains in the B-tree node cache. This can lead to the log writer incorrectly proces…","severity":"medium","cvss":5.5,"cvssVector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","cvssSource":"vendor","cwe":"CWE-787","vendor":"Red Hat","product":"Linux","affected":["Linux >= 36a580eb489f54d81a0534974962e732a314b999 < 39005fd1ce654ffdecacddc406b9a038efe606e6","Linux >= 36a580eb489f54d81a0534974962e732a314b999 < bf49e6f6ddc12445a0330708b365de6458085980","Linux >= 36a580eb489f54d81a0534974962e732a314b999 < 4a1bb1f9f24a935c9b3f4fbf98012fa6d4ad826d","Linux >= 36a580eb489f54d81a0534974962e732a314b999 < b313edfbc0c2a60f7ce09b2e81ee71909ab8ddaf","Linux >= 36a580eb489f54d81a0534974962e732a314b999 < 5d3783c451a546373662ee11ec17019273e68034","Linux >= 36a580eb489f54d81a0534974962e732a314b999 < 448636c745a3f3b8582a0b8ce718c890a11c0fa9","Linux >= 36a580eb489f54d81a0534974962e732a314b999 < 28362e8ce51377afdec1782e661e808328a10514","Linux >= 36a580eb489f54d81a0534974962e732a314b999 < 45662dedb8f272ef7f16e69f13424c4bd0399240","Linux 2.6.30"],"published":"2026-09-11","updated":"2026-09-22","sourceUpdated":"2026-09-22T03:00:01+00:00","source":"CSAF","sourceUrl":"https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-89723.json","references":[{"url":"https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-89723.json"},{"url":"https://access.redhat.com/security/cve/CVE-2026-89723"},{"url":"https://bugzilla.redhat.com/show_bug.cgi?id=2532191"},{"url":"https://www.cve.org/CVERecord?id=CVE-2026-89723"},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2026-89723"},{"url":"https://git.kernel.org/pub/scm/linux/security/vulns.git/plain/cve/published/2026/CVE-2026-89723.mbox"},{"url":"https://git.kernel.org/stable/c/39005fd1ce654ffdecacddc406b9a038efe606e6"},{"url":"https://git.kernel.org/stable/c/bf49e6f6ddc12445a0330708b365de6458085980"},{"url":"https://git.kernel.org/stable/c/4a1bb1f9f24a935c9b3f4fbf98012fa6d4ad826d"},{"url":"https://git.kernel.org/stable/c/b313edfbc0c2a60f7ce09b2e81ee71909ab8ddaf"},{"url":"https://git.kernel.org/stable/c/5d3783c451a546373662ee11ec17019273e68034"},{"url":"https://git.kernel.org/stable/c/448636c745a3f3b8582a0b8ce718c890a11c0fa9"},{"url":"https://git.kernel.org/stable/c/28362e8ce51377afdec1782e661e808328a10514"},{"url":"https://git.kernel.org/stable/c/45662dedb8f272ef7f16e69f13424c4bd0399240"}],"tags":["csaf","vex","red-hat","cve.org","score-dispute"],"epss":0.00164,"epssPercentile":0.06024,"scores":{"vendor":5.5,"cna":7.8},"ingestedAt":"2026-09-14T15:23:07.449Z","slug":"CVE-2026-89723","body":"## Overview\n\nA flaw was found in the nilfs2 file system component of the Linux kernel. When a file is truncated, an intermediate node block is not properly deleted and remains in the B-tree node cache. This can lead to the log writer incorrectly processing the block, resulting in a slab-out-of-bounds memory access. A local attacker could potentially use this to cause memory corruption, leading to system instability or a denial of service.\n\n## Vendor advisories\n\n- **Red Hat VEX** · Moderate · updated 2026-09-22 · [vex](https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-89723.json)\n\n**kernel: nilfs2: fix slab-out-of-bounds in nilfs_direct_propagate after truncation** — rated Moderate by Red Hat. Released 2026-09-11, updated 2026-09-22.\n\nNot affected:\n\n- Red Hat Enterprise Linux 10\n- Red Hat Enterprise Linux 6\n- Red Hat Enterprise Linux 7\n- Red Hat Enterprise Linux 8\n- Red Hat Enterprise Linux 9\n- Red Hat OpenShift Container Platform 4\n\n## Remediation\n\nRefer to the advisory for fix availability.","depth":"sunlit","depthScore":30,"depthScoreParts":{"impact":30.3,"likelihood":0,"exploitation":0,"ransomware":0},"changes":[{"seq":208916,"id":"CVE-2026-89723","ts":1790062284429,"field":"cvss","old":"7.8","new":"5.5"},{"seq":208915,"id":"CVE-2026-89723","ts":1790062284429,"field":"severity","old":"high","new":"medium"},{"seq":197700,"id":"CVE-2026-89723","ts":1789384318464,"field":"cvss","old":"6.5","new":"7.8"},{"seq":197699,"id":"CVE-2026-89723","ts":1789384318464,"field":"severity","old":"medium","new":"high"},{"seq":183335,"id":"CVE-2026-89723","ts":1789356674915,"field":"cvss","old":"7.8","new":"6.5"},{"seq":183334,"id":"CVE-2026-89723","ts":1789356674915,"field":"severity","old":"high","new":"medium"},{"seq":153608,"id":"CVE-2026-89723","ts":1789285351485,"field":"cvss","old":null,"new":"7.8"},{"seq":153607,"id":"CVE-2026-89723","ts":1789285351485,"field":"severity","old":"none","new":"high"},{"seq":147598,"id":"CVE-2026-89723","ts":1789270211540,"field":"cvss","old":null,"new":"6.5"},{"seq":147597,"id":"CVE-2026-89723","ts":1789270211540,"field":"severity","old":"none","new":"medium"},{"seq":109356,"id":"CVE-2026-89723","ts":1789183731591,"field":"cvss","old":null,"new":"6.5"},{"seq":109355,"id":"CVE-2026-89723","ts":1789183731591,"field":"severity","old":"none","new":"medium"}]}