CVE-2026-90161

Summary

In the Linux kernel, the following vulnerability has been resolved:

erofs: fix interlaced ztailpacking pclusters

On-disk sizes of interlaced pclusters should be block-aligned, and ztailpacking interlaced pclusters should be invalid at all.

Currently, mkfs.erofs won't generate any interlaced pcluster with ztailpacking enabled, so this doesn't affect any existing valid filesystems.

However, crafted images can contain invalid interlaced ztailpacking pclusters, resulting in an out-of-bounds read from a kmap'd page and copying irrelevant kernel memory into userspace-visible page cache.

Affected Software

VendorProductVersion RangeStatus
LinuxLinuxfdffc091e6f94602558bba712b51bc16f79fd6d5 < ddb7ea4fd99bf6c4314d1dfca18aec6945ce8054affected
LinuxLinuxfdffc091e6f94602558bba712b51bc16f79fd6d5 < 451027c642e752420e1a04237db9ce7b35cee595affected
LinuxLinuxfdffc091e6f94602558bba712b51bc16f79fd6d5 < 862427ebb81d1f6abbf74d799790e1694b37b187affected
LinuxLinux7d6ef8277e44c22f894d54d26ddb36c22d60712daffected
LinuxLinux6.0.16 < 6.1affected
LinuxLinux6.1affected
LinuxLinux0 < 6.1unaffected
LinuxLinux6.18.52 <= 6.18.*unaffected
LinuxLinux7.2.6 <= 7.2.*unaffected
LinuxLinux7.3-rc1 <= *unaffected

Weaknesses

References