CVE-2026-43154: erofs: fix incorrect early exits in volume label handling
Published May 6, 2026
·Updated
In the Linux kernel, the following vulnerability has been resolved:
erofs: fix incorrect early exits in volume label handling
Crafted EROFS images containing valid volume labels can trigger incorrect early returns, leading to folio reference leaks.
However, this does not cause system crashes or other severe issues.
Affected Software
3 affected components
Linux Linux kernel (erofs)
Linux Linux kernel>=6.18<6.18.16
Linux Linux kernel>=6.19<6.19.6
Remediation
Event History
May 6, 2026
CVE Published
via MITRE·11:27 AM
Data Sourced
via MITRE·11:27 AM
Description
Data Sourced
via NVD·12:16 PM
RemedyDescriptionSeverityAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2026-43154?
CVE-2026-43154 has a medium severity rating of 5.5 according to the CVSS 3.1 score.
2
How do I fix CVE-2026-43154?
To resolve CVE-2026-43154, apply the available patch that addresses the early exit issue in volume label handling.
3
What systems are affected by CVE-2026-43154?
CVE-2026-43154 affects the Linux kernel specifically in the EROFS file system.
4
What are the consequences of CVE-2026-43154?
CVE-2026-43154 can lead to folio reference leaks, but it does not cause system crashes or other severe impacts.
5
When was CVE-2026-43154 published?
CVE-2026-43154 was published on May 6, 2026.