Executive brief
A vulnerability in the Linux kernel's EROFS file system could allow a local user to cause memory resource leaks by using specially crafted disk images. EROFS is a read-only file system often used in mobile devices and embedded systems. While this issue does not typically cause immediate system crashes, it can lead to gradual performance degradation or resource exhaustion over time.
Technical details
A vulnerability in the EROFS file system driver in the Linux kernel arises from incorrect early exit logic in the 'erofs_read_superblock' function when processing invalid metabox-enabled images. Specifically, when metadata compression is enabled, certain error conditions trigger a direct 'return' instead of jumping to the proper cleanup label ('goto out'). This results in folio reference leaks, as acquired resources are not properly released before the function exits. An attacker with the ability to mount a crafted EROFS image could exploit this to leak kernel memory resources. The issue has been patched by ensuring error paths correctly navigate to the cleanup routine.
Affected products
- Linux Linux Kernel 6.17 to 6.18.16, 6.19 to 6.19.6
Timeline
- 2026-05-06: disclosed
- 2026-05-06: advisory