{
  "affected": [
    {
      "ecosystem_specific": {
        "urgency": "not yet assigned"
      },
      "package": {
        "ecosystem": "Debian:12",
        "name": "linux"
      },
      "ranges": [
        {
          "events": [
            {
              "introduced": "0"
            },
            {
              "fixed": "6.1.180-1"
            }
          ],
          "type": "ECOSYSTEM"
        }
      ]
    },
    {
      "ecosystem_specific": {
        "urgency": "not yet assigned"
      },
      "package": {
        "ecosystem": "Debian:13",
        "name": "linux"
      },
      "ranges": [
        {
          "events": [
            {
              "introduced": "0"
            },
            {
              "fixed": "6.12.96-1"
            }
          ],
          "type": "ECOSYSTEM"
        }
      ]
    },
    {
      "ecosystem_specific": {
        "urgency": "not yet assigned"
      },
      "package": {
        "ecosystem": "Debian:14",
        "name": "linux"
      },
      "ranges": [
        {
          "events": [
            {
              "introduced": "0"
            },
            {
              "fixed": "7.1.4-1"
            }
          ],
          "type": "ECOSYSTEM"
        }
      ]
    },
    {
      "ecosystem_specific": {
        "urgency": "not yet assigned"
      },
      "package": {
        "ecosystem": "Debian:12",
        "name": "linux-6.12"
      },
      "ranges": [
        {
          "events": [
            {
              "introduced": "0"
            },
            {
              "fixed": "6.12.100-1~deb12u1"
            }
          ],
          "type": "ECOSYSTEM"
        }
      ]
    }
  ],
  "details": "In the Linux kernel, the following vulnerability has been resolved:  nilfs2: reject CLEAN_SEGMENTS ioctl with out-of-range segment numbers  Syzbot reported a hung task in nilfs_transaction_begin() where multiple tasks performing chmod() on a nilfs2 mount blocked for over 143 seconds waiting to acquire ns_segctor_sem for read:    INFO: task syz.0.17:5918 blocked for more than 143 seconds.   Call Trace:    schedule+0x164/0x360    rwsem_down_read_slowpath+0x6d9/0x940    down_read+0x99/0x2e0    nilfs_transaction_begin+0x364/0x710 fs/nilfs2/segment.c:221    nilfs_setattr+0x124/0x2c0 fs/nilfs2/inode.c:921    notify_change+0xc1a/0xf40    chmod_common+0x273/0x4a0    do_fchmodat+0x12d/0x230  The writer holding ns_segctor_sem was a concurrent NILFS_IOCTL_CLEAN_SEGMENTS caller, stuck inside printk while emitting per-element warnings from nilfs_sufile_updatev():     __nilfs_msg+0x373/0x450 fs/nilfs2/super.c:78    nilfs_sufile_updatev+0x21c/0x6d0 fs/nilfs2/sufile.c:186    nilfs_sufile_freev fs/nilfs2/sufile.h:93 [inline]    nilfs_free_segments fs/nilfs2/segment.c:1140 [inline]    nilfs_segctor_collect_blocks fs/nilfs2/segment.c:1261 [inline]    nilfs_segctor_do_construct+0x1f55/0x76c0    nilfs_clean_segments+0x3bd/0xa50    nilfs_ioctl_clean_segments fs/nilfs2/ioctl.c:922 [inline]    nilfs_ioctl+0x261f/0x2780  The root cause is that user-supplied segment numbers are not validated before nilfs_clean_segments() begins doing work; the range check on each segnum is performed deep inside the call chain by nilfs_sufile_updatev(), which emits a nilfs_warn() per invalid entry while still holding the segctor lock and the sufile mi_sem.  Under load (repeated invocations across multiple mounts saturating the global printk path), the cumulative printk latency keeps ns_segctor_sem held long enough to trip the hung_task watchdog, blocking concurrent operations such as chmod() that need ns_segctor_sem for read.  Fix by validating the contents of kbufs[4] in nilfs_clean_segments() immediately after acquiring ns_segctor_sem via nilfs_transaction_lock(). Holding ns_segctor_sem serializes the check against nilfs_ioctl_resize(), which can modify ns_nsegments, so the validation uses a consistent value.  Out-of-range segment numbers are rejected with -EINVAL before any segment-cleaning work begins, so the bad entries never reach the per-element diagnostic path inside nilfs_sufile_updatev().",
  "id": "DEBIAN-CVE-2026-64359",
  "modified": "2026-09-14T16:47:32.465766455Z",
  "published": "2026-07-25T10:17:18.377Z",
  "references": [
    {
      "type": "ADVISORY",
      "url": "https://security-tracker.debian.org/tracker/CVE-2026-64359"
    }
  ],
  "severity": [
    {
      "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H",
      "type": "CVSS_V3"
    }
  ],
  "upstream": [
    "CVE-2026-64359"
  ]
}