« Volver al listado

CVE-2026-98005

Estado: RecibidaSin puntuar—

In the Linux kernel, the following vulnerability has been resolved:

erofs: delimit inode_share cache key components

Previously, inode_share keys were encoded as follows:

It would be better to have a separator between the fingerprint and domain ID so that the fingerprint won't be parsed as part of a domain ID.

Change the key encoding as follows:

Since domain_id is a NUL-terminated string, this makes the in-memory key indices unambiguous.

Detalles técnicos trazas, registros y código del informe original
  fingerprint || domain_id

  domain_id || '\0' || fingerprint

CVSS

NVD no ha asignado puntuación CVSS a esta CVE (habitual desde el cambio de política de abril de 2026).

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (1)

⚠ Inferidas por IA a partir de la descripción — NVD aún no ha analizado esta CVE; no son CPE verificados.

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2026-98005",
  "cveTags": [],
  "metrics": {},
  "affected": [
    {
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
      "affectedData": [
        {
          "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
          "vendor": "Linux",
          "product": "Linux",
          "versions": [
            {
              "status": "affected",
              "version": "e0bf7d1c074dc4252223ae897560345ccc24100d",
              "lessThan": "16322a67336cfeea0af4b05206ef8d0e0eda55bb",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "e0bf7d1c074dc4252223ae897560345ccc24100d",
              "lessThan": "96bf9831fbf423b8104f7948cd8fe7007ecfb46c",
              "versionType": "git"
            }
          ],
          "programFiles": [
            "fs/erofs/xattr.c"
          ],
          "defaultStatus": "unaffected"
        },
        {
          "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
          "vendor": "Linux",
          "product": "Linux",
          "versions": [
            {
              "status": "affected",
              "version": "7.0"
            },
            {
              "status": "unaffected",
              "version": "0",
              "lessThan": "7.0",
              "versionType": "semver"
            },
            {
              "status": "unaffected",
              "version": "7.2.7",
              "versionType": "semver",
              "lessThanOrEqual": "7.2.*"
            },
            {
              "status": "unaffected",
              "version": "7.3-rc3",
              "versionType": "original_commit_for_fix",
              "lessThanOrEqual": "*"
            }
          ],
          "programFiles": [
            "fs/erofs/xattr.c"
          ],
          "defaultStatus": "affected"
        }
      ]
    }
  ],
  "published": "2026-09-25T11:17:28.740",
  "references": [
    {
      "url": "https://git.kernel.org/stable/c/16322a67336cfeea0af4b05206ef8d0e0eda55bb",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/96bf9831fbf423b8104f7948cd8fe7007ecfb46c",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    }
  ],
  "vulnStatus": "Received",
  "descriptions": [
    {
      "lang": "en",
      "value": "In the Linux kernel, the following vulnerability has been resolved:\n\nerofs: delimit inode_share cache key components\n\nPreviously, inode_share keys were encoded as follows:\n\n  fingerprint || domain_id\n\nIt would be better to have a separator between the fingerprint and domain\nID so that the fingerprint won't be parsed as part of a domain ID.\n\nChange the key encoding as follows:\n\n  domain_id || '\\0' || fingerprint\n\nSince domain_id is a NUL-terminated string, this makes the in-memory key\nindices unambiguous."
    }
  ],
  "lastModified": "2026-09-25T11:17:28.740",
  "sourceIdentifier": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
}