---
id: CVE-2026-89723
title: >-
  kernel: nilfs2: fix slab-out-of-bounds in nilfs_direct_propagate after
  truncation (CVE-2026-89723)
summary: >-
  A flaw was found in the nilfs2 file system component of the Linux kernel. When
  a file is truncated, an intermediate node block is not properly deleted and
  remains in the B-tree node cache. This can lead to the log writer incorrectly
  proces…
severity: medium
cvss: 5.5
cvssVector: 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H'
cvssSource: vendor
cwe: CWE-787
vendor: Red Hat
product: Linux
affected:
  - >-
    Linux >= 36a580eb489f54d81a0534974962e732a314b999 <
    39005fd1ce654ffdecacddc406b9a038efe606e6
  - >-
    Linux >= 36a580eb489f54d81a0534974962e732a314b999 <
    bf49e6f6ddc12445a0330708b365de6458085980
  - >-
    Linux >= 36a580eb489f54d81a0534974962e732a314b999 <
    4a1bb1f9f24a935c9b3f4fbf98012fa6d4ad826d
  - >-
    Linux >= 36a580eb489f54d81a0534974962e732a314b999 <
    b313edfbc0c2a60f7ce09b2e81ee71909ab8ddaf
  - >-
    Linux >= 36a580eb489f54d81a0534974962e732a314b999 <
    5d3783c451a546373662ee11ec17019273e68034
  - >-
    Linux >= 36a580eb489f54d81a0534974962e732a314b999 <
    448636c745a3f3b8582a0b8ce718c890a11c0fa9
  - >-
    Linux >= 36a580eb489f54d81a0534974962e732a314b999 <
    28362e8ce51377afdec1782e661e808328a10514
  - >-
    Linux >= 36a580eb489f54d81a0534974962e732a314b999 <
    45662dedb8f272ef7f16e69f13424c4bd0399240
  - Linux 2.6.30
published: '2026-09-11'
updated: '2026-09-22'
sourceUpdated: '2026-09-22T03:00:01+00:00'
source: CSAF
sourceUrl: 'https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-89723.json'
references:
  - url: >-
      https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-89723.json
  - url: 'https://access.redhat.com/security/cve/CVE-2026-89723'
  - url: 'https://bugzilla.redhat.com/show_bug.cgi?id=2532191'
  - url: 'https://www.cve.org/CVERecord?id=CVE-2026-89723'
  - url: 'https://nvd.nist.gov/vuln/detail/CVE-2026-89723'
  - url: >-
      https://git.kernel.org/pub/scm/linux/security/vulns.git/plain/cve/published/2026/CVE-2026-89723.mbox
  - url: 'https://git.kernel.org/stable/c/39005fd1ce654ffdecacddc406b9a038efe606e6'
  - url: 'https://git.kernel.org/stable/c/bf49e6f6ddc12445a0330708b365de6458085980'
  - url: 'https://git.kernel.org/stable/c/4a1bb1f9f24a935c9b3f4fbf98012fa6d4ad826d'
  - url: 'https://git.kernel.org/stable/c/b313edfbc0c2a60f7ce09b2e81ee71909ab8ddaf'
  - url: 'https://git.kernel.org/stable/c/5d3783c451a546373662ee11ec17019273e68034'
  - url: 'https://git.kernel.org/stable/c/448636c745a3f3b8582a0b8ce718c890a11c0fa9'
  - url: 'https://git.kernel.org/stable/c/28362e8ce51377afdec1782e661e808328a10514'
  - url: 'https://git.kernel.org/stable/c/45662dedb8f272ef7f16e69f13424c4bd0399240'
tags:
  - csaf
  - vex
  - red-hat
  - cve.org
  - score-dispute
epss: 0.00176
epssPercentile: 0.06319
scores:
  vendor: 5.5
  cna: 7.8
ingestedAt: '2026-09-14T15:23:07.449Z'
---

## Overview

A flaw was found in the nilfs2 file system component of the Linux kernel. When a file is truncated, an intermediate node block is not properly deleted and remains in the B-tree node cache. This can lead to the log writer incorrectly processing the block, resulting in a slab-out-of-bounds memory access. A local attacker could potentially use this to cause memory corruption, leading to system instability or a denial of service.

## Vendor advisories

- **Red Hat VEX** · Moderate · updated 2026-09-22 · [vex](https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-89723.json)

**kernel: nilfs2: fix slab-out-of-bounds in nilfs_direct_propagate after truncation** — rated Moderate by Red Hat. Released 2026-09-11, updated 2026-09-22.

Not affected:

- Red Hat Enterprise Linux 10
- Red Hat Enterprise Linux 6
- Red Hat Enterprise Linux 7
- Red Hat Enterprise Linux 8
- Red Hat Enterprise Linux 9
- Red Hat OpenShift Container Platform 4

## Remediation

Refer to the advisory for fix availability.
