Executive brief
A vulnerability exists in the Linux kernel's EROFS file system driver, which is used for reading compressed read-only file systems. By providing a specially crafted disk image, an attacker could cause the system to crash or behave unexpectedly. This issue primarily impacts system availability and could be used in local denial-of-service attacks.
Technical details
An unsigned integer underflow vulnerability exists in the z_erofs_lz4_handle_overlap() function within the EROFS file system driver of the Linux kernel. The flaw is triggered when processing crafted images with illegal extents where the number of output pages is less than the number of input pages (outpages < inpages). In the LZ4 inplace decompression path, the calculation 'outpages - inpages' wraps to a large value, causing a subsequent out-of-bounds read past the decompressed_pages array. This can result in a kernel oops or system instability. The fix introduces a check to ensure outpages is greater than or equal to inpages before proceeding with inplace decompression.
Affected products
- Linux Linux Kernel Fixed in 21e161d, 43a8786, bbbbb3f, c9ce18e, f1374fa
Timeline
- 2026-04-09: other: Patch authored
- 2026-05-27: disclosed: CVE published
References
- https://git.kernel.org/stable/c/21e161de2dc660b1bb70ef5b156ab8e6e1cca3ab
- https://git.kernel.org/stable/c/43a878639b90e9721ffa5eb616a7e6d8454adef3
- https://git.kernel.org/stable/c/bbbbb3f0d7864238a8da2a94cd6ec013fee06a2e
- https://git.kernel.org/stable/c/c9ce18e6bb2c467ec85756dc7989b547b7584fee
- https://git.kernel.org/stable/c/f1374fa6e57fd836623668d782ded9244cfd2938