Junglewise Threat Intelligence

CVE-2026-64146: Linux Kernel EROFS metabuf leak in inode xattr initialization

CVE-2026-64146 · Severity: info · CVSS 0 · Published 2026-07-19

Technologies: Linux Kernel. Vendors: Linux.

Executive brief

A vulnerability was identified in the Linux kernel's EROFS file system, which is commonly used in read-only environments like mobile devices and embedded systems. A technical error in how the system handles file attributes could lead to a memory leak, potentially slowing down or destabilizing the system over time. This issue has been resolved in recent kernel updates.

Technical details

A resource leak exists in the EROFS file system implementation within the Linux kernel. Specifically, the function `erofs_init_inode_xattrs()` fails to release a metadata buffer (`metabuf`) in certain error paths after calling `erofs_read_metabuf()`. This results in a folio reference leak. The vulnerability was introduced when xattr operations were converted to use on-stack `erofs_buf` instances. An attacker with local access could potentially trigger these error paths to cause gradual memory exhaustion. The fix consolidates the cleanup logic at the `out_unlock` label to ensure `erofs_put_metabuf()` is always called.

Affected products

  • Linux Linux Kernel 5.17 to 7.0.11

Timeline

  • 2026-05-20: patched: Initial patch authored
  • 2026-07-19: disclosed: CVE published

References

Related threats