{"id":"AZL-102522","summary":"CVE-2026-90418 affecting package kernel 6.6.150.1-1","details":"In the Linux kernel, the following vulnerability has been resolved:\n\nnilfs2: fix BUG in nilfs_copy_dirty_pages() on dirty state mismatch\n\nSyzbot reported a kernel BUG triggered within nilfs_copy_dirty_pages(),\nwhich copies dirty DAT file folios/pages to its shadow page cache.  The\nBUG occurs when a retrieved dirty folio/page unexpectedly loses its\n'dirty' status.\n\nThis issue arises because, since the commit referenced below, the 'dirty'\nflag of a folio/page can be cleared asynchronously after the filesystem\ndetects metadata corruption and transitions to read-only mode.\n\nResolve the issue by returning an -EROFS error if the filesystem has\ntransitioned to read-only mode.  Also change the behavior to issue a\nkernel warning only once instead of triggering a kernel BUG when this\nunexpected 'dirty' state is detected while the filesystem is not in\nread-only mode.","modified":"2026-09-18T14:17:50.450757240Z","published":"2026-09-17T17:17:46Z","upstream":["CVE-2026-90418"],"references":[{"type":"WEB","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-90418"}],"affected":[{"package":{"name":"kernel","ecosystem":"Azure Linux:3","purl":"pkg:rpm/azure-linux/kernel"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"last_affected":"6.6.150.1-1"}]}],"database_specific":{"source":"https://github.com/microsoft/AzureLinuxVulnerabilityData/blob/main/osv/AZL-102522.json"}}],"schema_version":"1.9.0"}