CVE-2026-45943: erofs: fix inline data read failure for ztailpacking pclusters
erofs: fix inline data read failure for ztailpacking pclusters
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Compensating control
For EROFS ztailpacking pclusters, read the inline data before allocating the pclusters and adding them to the I/O chains.
Event History
Frequently Asked Questions
Which systems are exposed to this issue?
Systems using the Linux kernel's EROFS implementation with compressed ztailpacking pclusters and inline data are the affected context described. The failure concerns reading inline data for those pclusters.
What access is required to exploit the issue?
The CVSS vector classifies the attack as local, requiring low privileges and no user interaction. The described failure can occur when a fatal signal arrives while read_mapping_folio() is running.
What is the likely impact?
The failure can cause a kernel NULL pointer dereference in z_erofs_decompress_queue(). The supplied CVSS assessment rates confidentiality and availability impact as high.
How can administrators identify a possible occurrence?
Kernel logs may include "z_erofs_pcluster_begin: failed to get inline data -4" followed by an "Unable to handle kernel NULL pointer dereference" message. A stack trace may identify z_erofs_decompress_queue as the faulting function.