Impact
An internal kernel bug in the eROFS filesystem leads to a NULL pointer dereference during decompression of compressed pclusters that contain invalid inline data. The resulting kernel crash can stop all processes on the affected system. The flaw is exposed during normal read operations on an eROFS mount and may be triggered by a crafted file structure. No information about remote exploitation or privilege escalation is present in the supplied data.
Affected Systems
The vulnerability may affect any Linux kernel with eROFS support that has not incorporated commit 5de1aa0bf3a5db0b3cbf61959da5ac61250833ed. Based on the description, it is inferred that distributions which ship a kernel with eROFS enabled and that may use eROFS volumes, such as recent Ubuntu, Debian, Fedora, and others, could be impacted. No specific kernel versions are listed, so any unpatched release that includes eROFS is at risk.
Risk and Exploitability
The vulnerability carries a moderate severity due to the kernel crash it can cause. The CVSS score is 5.5, EPSS score is < 1%, and it is not cataloged in CISA KEV. Based on the description, it is inferred that the attack vector is local: an attacker must provide a malicious file on an eROFS mount to trigger the bug. While no exploits are published, the potential for denial of service warrants proactive remediation.
OpenCVE Enrichment