PT-2026-86183 · Linux · Linux
CVE-2026-80892
·
Publicado
2026-09-04
·
Atualizado
2026-09-11
Nenhuma
Não há classificações de severidade ou métricas disponíveis. Quando houver, atualizaremos as informações correspondentes na página.
In the Linux kernel, the following vulnerability has been resolved:
erofs: cap LZMA stream pool size
fs/erofs/decompressor lzma.c sizes the module-global MicroLZMA stream
pool from num possible cpus() when the lzma streams module parameter is
unset, then z erofs load lzma config() preallocates one image-supplied
dictionary per stream, accepting dictionaries up to 8 MiB. On high-CPU
systems, a small EROFS image can pin hundreds of MiB of vmalloc-backed
decoder state until the erofs module is unloaded.
Impact: An EROFS image mounted by the system can pin up to 8 MiB of
vmalloc memory per LZMA stream, either as intended or unexpectedly.
Bound the default stream count by a new
CONFIG EROFS FS ZIP LZMA DEFAULT MAX STREAMS option, default 16, so the
worst-case default preallocation is 128 MiB if the number of CPUs is no
less than 16 while preserving the existing per-image dictionary limit.
An explicit lzma streams module parameter is still honoured as-is, so
administrators who deliberately size the pool are not affected.
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Identificadores relacionados
Produtos afetados
Linux