Executive brief
The erofs filesystem driver in the Linux kernel failed to validate a critical index value when parsing compressed filesystem images, allowing a maliciously crafted image to trigger an out-of-bounds memory access. An attacker who can mount a crafted erofs image—either locally or through a compromised storage source—can crash the system or potentially execute code in kernel context.
Technical details
The vulnerability is an input validation failure in the erofs filesystem driver (fs/erofs/zmap.c) in the legacy_load_cluster_from_disk() function. When parsing non-compact HEAD index entries, the code reads a clusterofs value from disk and uses it without validating that it falls within the valid range (0 to lclustersize-1). A syzbot-generated crafted image with a clusterofs of 33024 caused out-of-bounds memory access during decompression, triggering a page fault in z_erofs_decompress_queue(). The attack requires the ability to mount a malicious erofs image, which can be achieved locally or via network-accessible storage. The fix adds a bounds check that returns -EFSCORRUPTED if clusterofs exceeds the maximum valid value. Patches have been merged into mainline and stable kernel branches as of May 2023.
Affected products
- Linux Linux kernel Linux 4.18 through 6.3 (affected versions vary by stable branch)
Timeline
- 2023-04-11: disclosed: Vulnerability discovered by syzbot and reported to kernel developers
- 2023-05-11: patched: Fix merged into stable kernels via commit 060fecf1114ff9fcfe87953fe8c4fc5048777160
- 2025-12-24: advisory: CVE-2023-54132 disclosed to NVD