« Volver al listado

CVE-2026-80892

Estado: RecibidaSin puntuar—

In the Linux kernel, the following vulnerability has been resolved:

erofs: cap LZMA stream pool size

fs/erofs/decompressor_lzma.c sizes the module-global MicroLZMA stream pool from num_possible_cpus() when the lzma_streams module parameter is unset, then z_erofs_load_lzma_config() preallocates one image-supplied dictionary per stream, accepting dictionaries up to 8 MiB. On high-CPU systems, a small EROFS image can pin hundreds of MiB of vmalloc-backed decoder state until the erofs module is unloaded.

Impact: An EROFS image mounted by the system can pin up to 8 MiB of vmalloc memory per LZMA stream, either as intended or unexpectedly.

Leer descripción completaMostrar menos

Bound the default stream count by a new CONFIG_EROFS_FS_ZIP_LZMA_DEFAULT_MAX_STREAMS option, default 16, so the worst-case default preallocation is 128 MiB if the number of CPUs is no less than 16 while preserving the existing per-image dictionary limit. An explicit lzma_streams module parameter is still honoured as-is, so administrators who deliberately size the pool are not affected.

CVSS

NVD no ha asignado puntuación CVSS a esta CVE (habitual desde el cambio de política de abril de 2026).

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (1)

⚠ Inferidas por IA a partir de la descripción — NVD aún no ha analizado esta CVE; no son CPE verificados.

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2026-80892",
  "cveTags": [],
  "metrics": {},
  "affected": [
    {
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
      "affectedData": [
        {
          "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
          "vendor": "Linux",
          "product": "Linux",
          "versions": [
            {
              "status": "affected",
              "version": "622ceaddb7649ca328832f50ba1400af778d75fa",
              "lessThan": "682cb3ece37fc5141e73bc726ccf4adb833e5189",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "622ceaddb7649ca328832f50ba1400af778d75fa",
              "lessThan": "e8b3d09aa8889dda9be9cbb3d2f0218c4b9acde4",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "622ceaddb7649ca328832f50ba1400af778d75fa",
              "lessThan": "0c676903cb2a61992ded8e7907609cc6b0f11744",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "622ceaddb7649ca328832f50ba1400af778d75fa",
              "lessThan": "5aaa06dfc10f8398c8807453dbec738ea9af10e4",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "622ceaddb7649ca328832f50ba1400af778d75fa",
              "lessThan": "e52da169b8c0d19bb2d803f2a07fe0e5a00462d6",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "622ceaddb7649ca328832f50ba1400af778d75fa",
              "lessThan": "c9b47e6b23114e939b17f818471c7a46e59006e7",
              "versionType": "git"
            }
          ],
          "programFiles": [
            "fs/erofs/Kconfig",
            "fs/erofs/decompressor_lzma.c"
          ],
          "defaultStatus": "unaffected"
        },
        {
          "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
          "vendor": "Linux",
          "product": "Linux",
          "versions": [
            {
              "status": "affected",
              "version": "5.16"
            },
            {
              "status": "unaffected",
              "version": "0",
              "lessThan": "5.16",
              "versionType": "semver"
            },
            {
              "status": "unaffected",
              "version": "6.1.184",
              "versionType": "semver",
              "lessThanOrEqual": "6.1.*"
            },
            {
              "status": "unaffected",
              "version": "6.6.151",
              "versionType": "semver",
              "lessThanOrEqual": "6.6.*"
            },
            {
              "status": "unaffected",
              "version": "6.12.103",
              "versionType": "semver",
              "lessThanOrEqual": "6.12.*"
            },
            {
              "status": "unaffected",
              "version": "6.18.44",
              "versionType": "semver",
              "lessThanOrEqual": "6.18.*"
            },
            {
              "status": "unaffected",
              "version": "7.1.8",
              "versionType": "semver",
              "lessThanOrEqual": "7.1.*"
            },
            {
              "status": "unaffected",
              "version": "7.2",
              "versionType": "original_commit_for_fix",
              "lessThanOrEqual": "*"
            }
          ],
          "programFiles": [
            "fs/erofs/Kconfig",
            "fs/erofs/decompressor_lzma.c"
          ],
          "defaultStatus": "affected"
        }
      ]
    }
  ],
  "published": "2026-09-04T18:17:57.337",
  "references": [
    {
      "url": "https://git.kernel.org/stable/c/0c676903cb2a61992ded8e7907609cc6b0f11744",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/5aaa06dfc10f8398c8807453dbec738ea9af10e4",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/682cb3ece37fc5141e73bc726ccf4adb833e5189",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/c9b47e6b23114e939b17f818471c7a46e59006e7",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/e52da169b8c0d19bb2d803f2a07fe0e5a00462d6",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/e8b3d09aa8889dda9be9cbb3d2f0218c4b9acde4",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    }
  ],
  "vulnStatus": "Received",
  "descriptions": [
    {
      "lang": "en",
      "value": "In the Linux kernel, the following vulnerability has been resolved:\n\nerofs: cap LZMA stream pool size\n\nfs/erofs/decompressor_lzma.c sizes the module-global MicroLZMA stream\npool from num_possible_cpus() when the lzma_streams module parameter is\nunset, then z_erofs_load_lzma_config() preallocates one image-supplied\ndictionary per stream, accepting dictionaries up to 8 MiB.  On high-CPU\nsystems, a small EROFS image can pin hundreds of MiB of vmalloc-backed\ndecoder state until the erofs module is unloaded.\n\nImpact: An EROFS image mounted by the system can pin up to 8 MiB of\nvmalloc memory per LZMA stream, either as intended or unexpectedly.\n\nBound the default stream count by a new\nCONFIG_EROFS_FS_ZIP_LZMA_DEFAULT_MAX_STREAMS option, default 16, so the\nworst-case default preallocation is 128 MiB if the number of CPUs is no\nless than 16 while preserving the existing per-image dictionary limit.\nAn explicit lzma_streams module parameter is still honoured as-is, so\nadministrators who deliberately size the pool are not affected."
    }
  ],
  "lastModified": "2026-09-04T18:17:57.337",
  "sourceIdentifier": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
}