Description
In the Linux kernel, the following vulnerability has been resolved:

erofs: skip sufficiently large global buffers when resizing

z_erofs_gbuf_nrpages is advanced only after every global buffer has been
grown. If a resize fails after some buffers were enlarged, a retry
revisits those enlarged buffers.

Retrying the same size then returns -ENOMEM because alloc_pages_bulk()
has no pages to add and the unchanged return value is treated as a
failure. Retrying an intermediate size allocates a temporary pointer
array smaller than gbuf->nrpages and copies more existing pointers than
the array can hold.

Skip buffers that already satisfy the request. Once all remaining
buffers have caught up, advancing z_erofs_gbuf_nrpages again describes
the guaranteed minimum size across the pool.
Published: 2026-09-11
Score: 7.8 High
EPSS: < 1% Very Low
KEV: No
Impact: Kernel memory corruption
Action: Immediate Patch
AI Analysis

Impact

In the Linux kernel’s eRofs filesystem, resizing logic can allocate a temporary pointer array that is smaller than the number of pointers being copied into it. When a global buffer is enlarged and a subsequent resize fails, the kernel retries with the same size, leaving the temporary array undersized. This results in an out-of-bounds copy that corrupts kernel memory. The CVE description does not identify an exploitation that achieves code execution, but the metadata, or lead to kernel panic.

Affected Systems

All Linux kernel installations that support the eRofs filesystem and have not applied the upstream patch are potentially affected. The vendor list indicates the Linux kernel itself; specific kernel versions are not provided, so any kernel version prior to the upstream fix is at risk.

Risk and Exploitability

The vulnerability carries a CVSS score of 7.8 and an EPSS score below 1%, indicating high severity but a low probability of exploitation. The likely attack vector is local, inferred from the description, as the flaw arises during eRofs filesystem resizing when a failed resize leads to an out-of-bounds copy. An attacker would need to trigger such resizing, for example by accessing large or malformed erofs files. If exploitation succeeds, kernel memory corruption could cause crashes, instability, or potentially allow privilege escalation, but no documented code-execution exploit exists.

Generated by OpenCVE AI on September 15, 2026 at 21:26 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade to a Linux kernel release that includes the upstream eRofs resize fix.
  • If an immediate upgrade is not possible, restrict or disable the eRofs filesystem or avoid mounting untrusted erofs images.
  • Monitor system stability and kernel logs for abnormal out-of-memory errors or crash indicators that could signal memory corruption events.

Generated by OpenCVE AI on September 15, 2026 at 21:26 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Debian DSA Debian DSA DSA-6528-1 linux security update
History

Mon, 21 Sep 2026 13:30:00 +0000


Sun, 13 Sep 2026 06:45:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 6.0, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:N/I:H/A:H'}

cvssV3_1

{'score': 7.8, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H'}


Sat, 12 Sep 2026 17:45:00 +0000

Type Values Removed Values Added
Weaknesses CWE-122

Sat, 12 Sep 2026 12:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-787
References
Metrics threat_severity

None

cvssV3_1

{'score': 6.0, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:N/I:H/A:H'}

threat_severity

Moderate


Sat, 12 Sep 2026 09:45:00 +0000

Type Values Removed Values Added
Weaknesses CWE-122

Fri, 11 Sep 2026 23:45:00 +0000

Type Values Removed Values Added
Description In the Linux kernel, the following vulnerability has been resolved: erofs: skip sufficiently large global buffers when resizing z_erofs_gbuf_nrpages is advanced only after every global buffer has been grown. If a resize fails after some buffers were enlarged, a retry revisits those enlarged buffers. Retrying the same size then returns -ENOMEM because alloc_pages_bulk() has no pages to add and the unchanged return value is treated as a failure. Retrying an intermediate size allocates a temporary pointer array smaller than gbuf->nrpages and copies more existing pointers than the array can hold. Skip buffers that already satisfy the request. Once all remaining buffers have caught up, advancing z_erofs_gbuf_nrpages again describes the guaranteed minimum size across the pool.
Title erofs: skip sufficiently large global buffers when resizing
First Time appeared Linux
Linux linux Kernel
CPEs cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
Vendors & Products Linux
Linux linux Kernel
References

Subscriptions

Linux Linux Kernel
cve-icon MITRE

Status: PUBLISHED

Assigner: Linux

Published:

Updated: 2026-09-21T13:14:33.615Z

Reserved: 2026-09-11T19:38:34.732Z

Link: CVE-2026-89602

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-09-11T20:19:45.117

Modified: 2026-09-21T14:17:23.817

Link: CVE-2026-89602

cve-icon Redhat

Severity : Moderate

Publid Date: 2026-09-11T19:45:05Z

Links: CVE-2026-89602 - Bugzilla

cve-icon OpenCVE Enrichment

Updated: 2026-09-15T21:30:16Z

Weaknesses