KernelScan.io

HIGH

erofs ZTailpacking OOB

CVE-2026-90161

CVSS 7.1 / 10.0 NVD

CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:H

KernelScan AI4.4MEDIUM

01

In the Linux kernel, the following vulnerability has been resolved: erofs: fix interlaced ztailpacking pclusters On-disk sizes of interlaced pclusters should be block-aligned, and ztailpacking interlaced pclusters should be invalid at all. Currently, mkfs.erofs won't generate any interlaced pcluster with ztailpacking enabled, so this doesn't affect any existing valid filesystems. However, crafted images can contain invalid interlaced ztailpacking pclusters, resulting in an out-of-bounds read from a kmap'd page and copying irrelevant kernel memory into userspace-visible page cache.

02

Engine v0.6.0

Risk summary

A crafted EROFS filesystem image with invalid interlaced ztailpacking pclusters causes an out-of-bounds read from a kmap'd page, leaking kernel memory into the userspace-visible page cache. Exploitation requires mounting a malicious image, which needs real CAP_SYS_ADMIN (EROFS is not userns-mountable). Devices that accept removable media or allow root to mount arbitrary images are at risk of kernel memory disclosure.

Affectedfs/erofs/decompressor.c, fs/erofs/zmap.c (erofs filesystem)

Vulnerability analysis

The EROFS filesystem parser fails to reject crafted images that combine ztailpacking with interlaced pclusters — a combination that valid formatting tools never produce but that an attacker can craft. When such an image is mounted and read, the decompression path computes an incorrect source offset, reading beyond the intended data and copying unrelated kernel memory into the page cache where userspace can observe it. The fix prevents ztailpacking mappings from being treated as interlaced and adds an alignment check so invalid images are rejected before any data is copied. Reaching this code requires mounting an EROFS image, which demands real root privileges; the image can be supplied via removable media or by a root user performing a manual mount.

03

BranchIntroducedFixed inPatch commit
6.18—6.18.52451027c642e7
mainline—7.3-rc1—
7.2—7.2.6862427ebb81d
6.06.0.166.1ddb7ea4fd99b