Impact
In the Linux kernel’s eRofs filesystem, resizing logic can allocate a temporary pointer array that is smaller than the number of pointers being copied into it. When a global buffer is enlarged and a subsequent resize fails, the kernel retries with the same size, leaving the temporary array undersized. This results in an out-of-bounds copy that corrupts kernel memory. The CVE description does not identify an exploitation that achieves code execution, but the metadata, or lead to kernel panic.
Affected Systems
All Linux kernel installations that support the eRofs filesystem and have not applied the upstream patch are potentially affected. The vendor list indicates the Linux kernel itself; specific kernel versions are not provided, so any kernel version prior to the upstream fix is at risk.
Risk and Exploitability
The vulnerability carries a CVSS score of 7.8 and an EPSS score below 1%, indicating high severity but a low probability of exploitation. The likely attack vector is local, inferred from the description, as the flaw arises during eRofs filesystem resizing when a failed resize leads to an out-of-bounds copy. An attacker would need to trigger such resizing, for example by accessing large or malformed erofs files. If exploitation succeeds, kernel memory corruption could cause crashes, instability, or potentially allow privilege escalation, but no documented code-execution exploit exists.
OpenCVE Enrichment
Debian DSA