erofs: cap LZMA stream pool size

Summary

CVECVE-2026-80892
StatePUBLISHED
AssignerLinux
Source PriorityCVE Program / NVD first with legacy fallback
Published2026-09-04 18:17:57 UTC
Updated2026-09-04 18:17:57 UTC
DescriptionIn the Linux kernel, the following vulnerability has been resolved: erofs: cap LZMA stream pool size fs/erofs/decompressor_lzma.c sizes the module-global MicroLZMA stream pool from num_possible_cpus() when the lzma_streams module parameter is unset, then z_erofs_load_lzma_config() preallocates one image-supplied dictionary per stream, accepting dictionaries up to 8 MiB. On high-CPU systems, a small EROFS image can pin hundreds of MiB of vmalloc-backed decoder state until the erofs module is unloaded. Impact: An EROFS image mounted by the system can pin up to 8 MiB of vmalloc memory per LZMA stream, either as intended or unexpectedly. Bound the default stream count by a new CONFIG_EROFS_FS_ZIP_LZMA_DEFAULT_MAX_STREAMS option, default 16, so the worst-case default preallocation is 128 MiB if the number of CPUs is no less than 16 while preserving the existing per-image dictionary limit. An explicit lzma_streams module parameter is still honoured as-is, so administrators who deliberately size the pool are not affected.

Risk And Classification

EPSS: 0.001730000 probability, percentile 0.068250000 (date 2026-09-07)

Vendor Declared Affected Products

SourceVendorProductVersionPlatforms
CNA Linux Linux affected 622ceaddb7649ca328832f50ba1400af778d75fa 682cb3ece37fc5141e73bc726ccf4adb833e5189 git Not specified
CNA Linux Linux affected 622ceaddb7649ca328832f50ba1400af778d75fa e8b3d09aa8889dda9be9cbb3d2f0218c4b9acde4 git Not specified
CNA Linux Linux affected 622ceaddb7649ca328832f50ba1400af778d75fa 0c676903cb2a61992ded8e7907609cc6b0f11744 git Not specified
CNA Linux Linux affected 622ceaddb7649ca328832f50ba1400af778d75fa 5aaa06dfc10f8398c8807453dbec738ea9af10e4 git Not specified
CNA Linux Linux affected 622ceaddb7649ca328832f50ba1400af778d75fa e52da169b8c0d19bb2d803f2a07fe0e5a00462d6 git Not specified
CNA Linux Linux affected 622ceaddb7649ca328832f50ba1400af778d75fa c9b47e6b23114e939b17f818471c7a46e59006e7 git Not specified
CNA Linux Linux affected 5.16 Not specified
CNA Linux Linux unaffected 5.16 semver Not specified
CNA Linux Linux unaffected 6.1.184 6.1.* semver Not specified
CNA Linux Linux unaffected 6.6.151 6.6.* semver Not specified
CNA Linux Linux unaffected 6.12.103 6.12.* semver Not specified
CNA Linux Linux unaffected 6.18.44 6.18.* semver Not specified
CNA Linux Linux unaffected 7.1.8 7.1.* semver Not specified
CNA Linux Linux unaffected 7.2 * original_commit_for_fix Not specified

References

ReferenceSourceLinkTags
git.kernel.org/stable/c/0c676903cb2a61992ded8e7907609cc6b0f11744 416baaa9-dc9f-4396-8d5f-8c081fb06d67 git.kernel.org
git.kernel.org/stable/c/e8b3d09aa8889dda9be9cbb3d2f0218c4b9acde4 416baaa9-dc9f-4396-8d5f-8c081fb06d67 git.kernel.org
git.kernel.org/stable/c/682cb3ece37fc5141e73bc726ccf4adb833e5189 416baaa9-dc9f-4396-8d5f-8c081fb06d67 git.kernel.org
git.kernel.org/stable/c/5aaa06dfc10f8398c8807453dbec738ea9af10e4 416baaa9-dc9f-4396-8d5f-8c081fb06d67 git.kernel.org
git.kernel.org/stable/c/c9b47e6b23114e939b17f818471c7a46e59006e7 416baaa9-dc9f-4396-8d5f-8c081fb06d67 git.kernel.org
git.kernel.org/stable/c/e52da169b8c0d19bb2d803f2a07fe0e5a00462d6 416baaa9-dc9f-4396-8d5f-8c081fb06d67 git.kernel.org
CVE Program record CVE.ORG www.cve.org canonical
NVD vulnerability detail NVD nvd.nist.gov canonical, analysis

© CVE.report 2026

Use of this information constitutes acceptance for use in an AS IS condition. There are NO warranties, implied or otherwise, with regard to this information or its use. Any use of this information is at the user's risk. It is the responsibility of user to evaluate the accuracy, completeness or usefulness of any information, opinion, advice or other content. EACH USER WILL BE SOLELY RESPONSIBLE FOR ANY consequences of his or her direct or indirect use of this web site. ALL WARRANTIES OF ANY KIND ARE EXPRESSLY DISCLAIMED. This site will NOT BE LIABLE FOR ANY DIRECT, INDIRECT or any other kind of loss.

CVE, CWE, and OVAL are registred trademarks of The MITRE Corporation and the authoritative source of CVE content is MITRE's CVE web site. This site includes MITRE data granted under the following license.

Free CVE JSON API cve.report/api

CVE.report and Source URL Uptime Status status.cve.report