Impact
The kernel defect permits a crafted eROFS filesystem to cause an out‑of‑bounds read from a kernel‑mapped page. An attacker can embed an interlaced ztailpacking pcluster that violates block alignment rules, causing the kernel to copy arbitrary memory into the page cache visible to user space. This leads to confidential kernel data being exposed to processes that read the affected filesystem.
Affected Systems
The vulnerability is limited to the eROFS filesystem implementation in the Linux kernel. Any distribution using a kernel that lacks the commit that enforces block alignment for interlaced pclusters is susceptible. No specific version list is provided, so all kernels prior to the fix are at risk.
Risk and Exploitability
The CVSS score of 7.1 indicates moderate severity; the EPSS score of less than 1% indicates a low probability of exploitation, and the vulnerability is not listed in the CISA KEV catalog. An attacker would need to create and present a malicious eROFS image, typically via local means such as removable media or a network share. The required conditions for exploitation are therefore limited to local access to the target’s filesystem handling routines, which reduces the likelihood of widespread attacks.
OpenCVE Enrichment