GHSA-9rf3-hx86-5f4pHighCVSS 8.4

In the Linux kernel, the following vulnerability has been resolved: erofs: validate the extent...

Published
December 24, 2025
Last Modified
August 4, 2026

🔗 CVE IDs covered (1)

📋 Description

In the Linux kernel, the following vulnerability has been resolved:

erofs: validate the extent length for uncompressed pclusters

syzkaller reported a KASAN use-after-free: https://syzkaller.appspot.com/bug?extid=2ae90e873e97f1faf6f2

The referenced fuzzed image actually has two issues:

  • m_pa == 0 as a non-inlined pcluster;
  • The logical length is longer than its physical length.

The first issue has already been addressed. This patch addresses the second issue by checking the extent length validity.

🔗 References (5)