CVE-2026-80892: erofs: cap LZMA stream pool size

Published Sep 4, 2026
·
Updated

In the Linux kernel, the following vulnerability has been resolved:

erofs: cap LZMA stream pool size

fs/erofs/decompressorlzma.c sizes the module-global MicroLZMA stream pool from numpossiblecpus() when the lzmastreams module parameter is unset, then zerofsloadlzmaconfig() preallocates one image-supplied dictionary per stream, accepting dictionaries up to 8 MiB. On high-CPU systems, a small EROFS image can pin hundreds of MiB of vmalloc-backed decoder state until the erofs module is unloaded.

Impact: An EROFS image mounted by the system can pin up to 8 MiB of vmalloc memory per LZMA stream, either as intended or unexpectedly.

Bound the default stream count by a new CONFIGEROFSFSZIPLZMADEFAULTMAXSTREAMS option, default 16, so the worst-case default preallocation is 128 MiB if the number of CPUs is no less than 16 while preserving the existing per-image dictionary limit. An explicit lzmastreams module parameter is still honoured as-is, so administrators who deliberately size the pool are not affected.

Affected Software

1 affected component
Linux Kernel

Remediation

Recommended actions to resolve this vulnerability, in priority order.

  1. Configuration

    Set CONFIG_EROFS_FS_ZIP_LZMA_DEFAULT_MAX_STREAMS to 16 to cap the default LZMA stream pool size (reduces vmalloc-backed decoder-state pinning by limiting the stream pool).

    Linux kernel erofs LZMA decompressor (fs/erofs/decompressor_lzma.c) CONFIG_EROFS_FS_ZIP_LZMA_DEFAULT_MAX_STREAMS = 16

Event History

Sep 4, 2026
CVE Published
via MITRE·05:11 PM
Data Sourced
via MITRE·05:11 PM
Description

Frequently Asked Questions

1

Which systems are most exposed to excessive memory use?

Systems that mount EROFS images using LZMA compression are exposed, particularly high-CPU systems where the default stream pool was derived from the number of possible CPUs. A small image can retain up to 8 MiB of vmalloc-backed decoder state for each stream until the erofs module is unloaded.

2

Does an explicitly configured lzma_streams value avoid the new limit?

Yes. An explicit lzma_streams module parameter continues to be honored as configured; the new limit applies to the default stream count when that parameter is unset.

3

What is the default memory bound after the fix?

The new CONFIG_EROFS_FS_ZIP_LZMA_DEFAULT_MAX_STREAMS option defaults to 16 streams. Where the system has at least 16 CPUs, this bounds default preallocation to 128 MiB while retaining the 8 MiB per-image dictionary limit.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203