PT-2026-61348 · Linux · Linux

CVE-2026-64031

·

Publicado

2026-07-19

·

Atualizado

2026-07-19

CVSS v3.1

7.8

Alta

VetorAV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
In the Linux kernel, the following vulnerability has been resolved:
erofs: fix managed cache race for unaligned extents
After unaligned compressed extents were introduced, the following race could occur:
[Thread 1] [Thread 2] (z erofs fill bio vec) ... filemap add folio (1) (z erofs bind cache) .. .. folio attach private (2) filemap add folio (3) again
Since (1) is executed but (2) hasn't been executed yet, it's possible that another thread finds the same managed folio in z erofs bind cache() for a different pcluster and calls filemap add folio() again since folio->private is still Z EROFS PREALLOCATED FOLIO.
Fix this by explicitly clearing folio->private before making the folio visible in the managed cache so that another pcluster can simply wait on the locked managed folio as what we did for other shared cases [1].
This only impacts unaligned data compression (-E48bit with zstd, for example).
[1] Commit 9e2f9d34dd12 ("erofs: handle overlapped pclusters out of crafted images properly") was originally introduced to handle crafted overlapped extents, but it addresses unaligned extents as well.

Correção

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Identificadores relacionados

CVE-2026-64031

Produtos afetados

Linux