Junglewise Threat Intelligence

CVE-2026-53272: Linux Kernel EROFS use-after-free in z_erofs_decompress_kickoff

CVE-2026-53272 · Severity: info · Published 2026-06-25

Technologies: Linux Kernel. Vendors: Linux.

Executive brief

A vulnerability was identified in the Linux kernel's EROFS file system driver that could lead to a system crash. The issue occurs when a file system is unmounted while background data decompression tasks are still being scheduled. This race condition can cause the system to attempt to access memory that has already been freed, potentially impacting system stability.

Technical details

A use-after-free (UAF) vulnerability exists in fs/erofs/zdata.c within the Linux kernel. The flaw is rooted in a race condition between z_erofs_decompress_kickoff() and the filesystem unmount process. When I/O completes, z_erofs_endio() triggers an asynchronous decompression work item; however, if the unmount workflow proceeds simultaneously, the super_block information (sbi) may be freed before the asynchronous worker finishes accessing sbi->sync_decompress. This local vulnerability requires the ability to mount/unmount EROFS filesystems and can result in a kernel oops or unpredictable system behavior. Patches have been released for various stable branches including 6.12.y, 6.18.y, and 7.0.y.

Affected products

  • Linux Linux Kernel 5.17 to 7.0.12

Timeline

  • 2026-06-25: advisory: CVE-2026-53272 published by kernel.org

References

Related threats