Executive brief
A vulnerability in the Linux kernel's EROFS file system handling could allow a local user to cause minor resource leaks. By using a specially crafted storage image, an attacker can trigger a condition where the system fails to properly release memory references. While this does not typically lead to a full system crash, it can degrade performance or lead to resource exhaustion over time.
Technical details
A vulnerability in the EROFS file system's `erofs_read_superblock` function in `fs/erofs/super.c` leads to folio reference leaks. When processing a crafted EROFS image with a valid volume label, an incorrect early return occurs if memory allocation for the volume name fails. This bypasses the standard cleanup path, preventing the release of folio references. An attacker with local privileges to mount or trigger the mounting of a crafted EROFS image can exploit this to cause a gradual resource leak, though it is reported not to cause immediate system crashes. Patches have been released for various stable kernel branches.
Affected products
- Linux Linux Kernel 6.18 to 6.18.16, 6.19 to 6.19.6
Timeline
- 2026-05-06: disclosed
- 2026-05-06: advisory