PT-2026-86183 · Linux · Linux

CVE-2026-80892

·

Publicado

2026-09-04

·

Atualizado

2026-09-11

Nenhuma

Não há classificações de severidade ou métricas disponíveis. Quando houver, atualizaremos as informações correspondentes na página.
In the Linux kernel, the following vulnerability has been resolved:
erofs: cap LZMA stream pool size
fs/erofs/decompressor lzma.c sizes the module-global MicroLZMA stream pool from num possible cpus() when the lzma streams module parameter is unset, then z erofs load lzma config() preallocates one image-supplied dictionary per stream, accepting dictionaries up to 8 MiB. On high-CPU systems, a small EROFS image can pin hundreds of MiB of vmalloc-backed decoder state until the erofs module is unloaded.
Impact: An EROFS image mounted by the system can pin up to 8 MiB of vmalloc memory per LZMA stream, either as intended or unexpectedly.
Bound the default stream count by a new CONFIG EROFS FS ZIP LZMA DEFAULT MAX STREAMS option, default 16, so the worst-case default preallocation is 128 MiB if the number of CPUs is no less than 16 while preserving the existing per-image dictionary limit. An explicit lzma streams module parameter is still honoured as-is, so administrators who deliberately size the pool are not affected.
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Identificadores relacionados

CVE-2026-80892

Produtos afetados

Linux