{"api_version":"1","generated_at":"2026-09-16T00:29:57+00:00","cve":"CVE-2026-80892","urls":{"html":"https://cve.report/CVE-2026-80892","api":"https://cve.report/api/cve/CVE-2026-80892.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2026-80892","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2026-80892"},"summary":{"title":"erofs: cap LZMA stream pool size","description":"In the Linux kernel, the following vulnerability has been resolved:\n\nerofs: cap LZMA stream pool size\n\nfs/erofs/decompressor_lzma.c sizes the module-global MicroLZMA stream\npool from num_possible_cpus() when the lzma_streams module parameter is\nunset, then z_erofs_load_lzma_config() preallocates one image-supplied\ndictionary per stream, accepting dictionaries up to 8 MiB.  On high-CPU\nsystems, a small EROFS image can pin hundreds of MiB of vmalloc-backed\ndecoder state until the erofs module is unloaded.\n\nImpact: An EROFS image mounted by the system can pin up to 8 MiB of\nvmalloc memory per LZMA stream, either as intended or unexpectedly.\n\nBound the default stream count by a new\nCONFIG_EROFS_FS_ZIP_LZMA_DEFAULT_MAX_STREAMS option, default 16, so the\nworst-case default preallocation is 128 MiB if the number of CPUs is no\nless than 16 while preserving the existing per-image dictionary limit.\nAn explicit lzma_streams module parameter is still honoured as-is, so\nadministrators who deliberately size the pool are not affected.","state":"PUBLISHED","assigner":"Linux","published_at":"2026-09-04 18:17:57","updated_at":"2026-09-04 18:17:57"},"problem_types":[],"metrics":[],"references":[{"url":"https://git.kernel.org/stable/c/0c676903cb2a61992ded8e7907609cc6b0f11744","name":"https://git.kernel.org/stable/c/0c676903cb2a61992ded8e7907609cc6b0f11744","refsource":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","tags":[],"title":"","mime":"","httpstatus":"","archivestatus":"0"},{"url":"https://git.kernel.org/stable/c/e8b3d09aa8889dda9be9cbb3d2f0218c4b9acde4","name":"https://git.kernel.org/stable/c/e8b3d09aa8889dda9be9cbb3d2f0218c4b9acde4","refsource":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","tags":[],"title":"","mime":"","httpstatus":"","archivestatus":"0"},{"url":"https://git.kernel.org/stable/c/682cb3ece37fc5141e73bc726ccf4adb833e5189","name":"https://git.kernel.org/stable/c/682cb3ece37fc5141e73bc726ccf4adb833e5189","refsource":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","tags":[],"title":"","mime":"","httpstatus":"","archivestatus":"0"},{"url":"https://git.kernel.org/stable/c/5aaa06dfc10f8398c8807453dbec738ea9af10e4","name":"https://git.kernel.org/stable/c/5aaa06dfc10f8398c8807453dbec738ea9af10e4","refsource":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","tags":[],"title":"","mime":"","httpstatus":"","archivestatus":"0"},{"url":"https://git.kernel.org/stable/c/c9b47e6b23114e939b17f818471c7a46e59006e7","name":"https://git.kernel.org/stable/c/c9b47e6b23114e939b17f818471c7a46e59006e7","refsource":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","tags":[],"title":"","mime":"","httpstatus":"","archivestatus":"0"},{"url":"https://git.kernel.org/stable/c/e52da169b8c0d19bb2d803f2a07fe0e5a00462d6","name":"https://git.kernel.org/stable/c/e52da169b8c0d19bb2d803f2a07fe0e5a00462d6","refsource":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","tags":[],"title":"","mime":"","httpstatus":"","archivestatus":"0"},{"url":"https://www.cve.org/CVERecord?id=CVE-2026-80892","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2026-80892","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[{"source":"CNA","vendor":"Linux","product":"Linux","version":"affected 622ceaddb7649ca328832f50ba1400af778d75fa 682cb3ece37fc5141e73bc726ccf4adb833e5189 git","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"affected 622ceaddb7649ca328832f50ba1400af778d75fa e8b3d09aa8889dda9be9cbb3d2f0218c4b9acde4 git","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"affected 622ceaddb7649ca328832f50ba1400af778d75fa 0c676903cb2a61992ded8e7907609cc6b0f11744 git","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"affected 622ceaddb7649ca328832f50ba1400af778d75fa 5aaa06dfc10f8398c8807453dbec738ea9af10e4 git","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"affected 622ceaddb7649ca328832f50ba1400af778d75fa e52da169b8c0d19bb2d803f2a07fe0e5a00462d6 git","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"affected 622ceaddb7649ca328832f50ba1400af778d75fa c9b47e6b23114e939b17f818471c7a46e59006e7 git","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"affected 5.16","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"unaffected 5.16 semver","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"unaffected 6.1.184 6.1.* semver","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"unaffected 6.6.151 6.6.* semver","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"unaffected 6.12.103 6.12.* semver","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"unaffected 6.18.44 6.18.* semver","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"unaffected 7.1.8 7.1.* semver","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"unaffected 7.2 * original_commit_for_fix","platforms":[]}],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[],"vendor_comments":[],"enrichments":{"kev":null,"epss":{"cve_year":"2026","cve_id":"80892","cve":"CVE-2026-80892","epss":"0.001730000","percentile":"0.068250000","score_date":"2026-09-07","updated_at":"2026-09-08 00:05:26"},"legacy_qids":[]},"source_records":{"cve_program":{"containers":{"cna":{"affected":[{"defaultStatus":"unaffected","product":"Linux","programFiles":["fs/erofs/Kconfig","fs/erofs/decompressor_lzma.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","vendor":"Linux","versions":[{"lessThan":"682cb3ece37fc5141e73bc726ccf4adb833e5189","status":"affected","version":"622ceaddb7649ca328832f50ba1400af778d75fa","versionType":"git"},{"lessThan":"e8b3d09aa8889dda9be9cbb3d2f0218c4b9acde4","status":"affected","version":"622ceaddb7649ca328832f50ba1400af778d75fa","versionType":"git"},{"lessThan":"0c676903cb2a61992ded8e7907609cc6b0f11744","status":"affected","version":"622ceaddb7649ca328832f50ba1400af778d75fa","versionType":"git"},{"lessThan":"5aaa06dfc10f8398c8807453dbec738ea9af10e4","status":"affected","version":"622ceaddb7649ca328832f50ba1400af778d75fa","versionType":"git"},{"lessThan":"e52da169b8c0d19bb2d803f2a07fe0e5a00462d6","status":"affected","version":"622ceaddb7649ca328832f50ba1400af778d75fa","versionType":"git"},{"lessThan":"c9b47e6b23114e939b17f818471c7a46e59006e7","status":"affected","version":"622ceaddb7649ca328832f50ba1400af778d75fa","versionType":"git"}]},{"defaultStatus":"affected","product":"Linux","programFiles":["fs/erofs/Kconfig","fs/erofs/decompressor_lzma.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","vendor":"Linux","versions":[{"status":"affected","version":"5.16"},{"lessThan":"5.16","status":"unaffected","version":"0","versionType":"semver"},{"lessThanOrEqual":"6.1.*","status":"unaffected","version":"6.1.184","versionType":"semver"},{"lessThanOrEqual":"6.6.*","status":"unaffected","version":"6.6.151","versionType":"semver"},{"lessThanOrEqual":"6.12.*","status":"unaffected","version":"6.12.103","versionType":"semver"},{"lessThanOrEqual":"6.18.*","status":"unaffected","version":"6.18.44","versionType":"semver"},{"lessThanOrEqual":"7.1.*","status":"unaffected","version":"7.1.8","versionType":"semver"},{"lessThanOrEqual":"*","status":"unaffected","version":"7.2","versionType":"original_commit_for_fix"}]}],"cpeApplicability":[{"nodes":[{"cpeMatch":[{"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionEndExcluding":"6.1.184","versionStartIncluding":"5.16","vulnerable":true},{"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionEndExcluding":"6.6.151","versionStartIncluding":"5.16","vulnerable":true},{"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionEndExcluding":"6.12.103","versionStartIncluding":"5.16","vulnerable":true},{"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionEndExcluding":"6.18.44","versionStartIncluding":"5.16","vulnerable":true},{"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionEndExcluding":"7.1.8","versionStartIncluding":"5.16","vulnerable":true},{"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionEndExcluding":"7.2","versionStartIncluding":"5.16","vulnerable":true}],"negate":false,"operator":"OR"}]}],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nerofs: cap LZMA stream pool size\n\nfs/erofs/decompressor_lzma.c sizes the module-global MicroLZMA stream\npool from num_possible_cpus() when the lzma_streams module parameter is\nunset, then z_erofs_load_lzma_config() preallocates one image-supplied\ndictionary per stream, accepting dictionaries up to 8 MiB.  On high-CPU\nsystems, a small EROFS image can pin hundreds of MiB of vmalloc-backed\ndecoder state until the erofs module is unloaded.\n\nImpact: An EROFS image mounted by the system can pin up to 8 MiB of\nvmalloc memory per LZMA stream, either as intended or unexpectedly.\n\nBound the default stream count by a new\nCONFIG_EROFS_FS_ZIP_LZMA_DEFAULT_MAX_STREAMS option, default 16, so the\nworst-case default preallocation is 128 MiB if the number of CPUs is no\nless than 16 while preserving the existing per-image dictionary limit.\nAn explicit lzma_streams module parameter is still honoured as-is, so\nadministrators who deliberately size the pool are not affected."}],"providerMetadata":{"dateUpdated":"2026-09-04T17:11:08.391Z","orgId":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","shortName":"Linux"},"references":[{"url":"https://git.kernel.org/stable/c/682cb3ece37fc5141e73bc726ccf4adb833e5189"},{"url":"https://git.kernel.org/stable/c/e8b3d09aa8889dda9be9cbb3d2f0218c4b9acde4"},{"url":"https://git.kernel.org/stable/c/0c676903cb2a61992ded8e7907609cc6b0f11744"},{"url":"https://git.kernel.org/stable/c/5aaa06dfc10f8398c8807453dbec738ea9af10e4"},{"url":"https://git.kernel.org/stable/c/e52da169b8c0d19bb2d803f2a07fe0e5a00462d6"},{"url":"https://git.kernel.org/stable/c/c9b47e6b23114e939b17f818471c7a46e59006e7"}],"title":"erofs: cap LZMA stream pool size","x_generator":{"engine":"bippy-1.2.0"}}},"cveMetadata":{"assignerOrgId":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","assignerShortName":"Linux","cveId":"CVE-2026-80892","datePublished":"2026-09-04T17:11:08.391Z","dateReserved":"2026-08-26T14:34:25.800Z","dateUpdated":"2026-09-04T17:11:08.391Z","state":"PUBLISHED"},"dataType":"CVE_RECORD","dataVersion":"5.2"},"nvd":{"publishedDate":"2026-09-04 18:17:57","lastModifiedDate":"2026-09-04 18:17:57","problem_types":[],"metrics":[],"configurations":[]},"legacy_mitre":{"record":{"CveYear":"2026","CveId":"80892","Ordinal":"1","Title":"erofs: cap LZMA stream pool size","CVE":"CVE-2026-80892","Year":"2026"},"notes":[{"CveYear":"2026","CveId":"80892","Ordinal":"1","NoteData":"In the Linux kernel, the following vulnerability has been resolved:\n\nerofs: cap LZMA stream pool size\n\nfs/erofs/decompressor_lzma.c sizes the module-global MicroLZMA stream\npool from num_possible_cpus() when the lzma_streams module parameter is\nunset, then z_erofs_load_lzma_config() preallocates one image-supplied\ndictionary per stream, accepting dictionaries up to 8 MiB.  On high-CPU\nsystems, a small EROFS image can pin hundreds of MiB of vmalloc-backed\ndecoder state until the erofs module is unloaded.\n\nImpact: An EROFS image mounted by the system can pin up to 8 MiB of\nvmalloc memory per LZMA stream, either as intended or unexpectedly.\n\nBound the default stream count by a new\nCONFIG_EROFS_FS_ZIP_LZMA_DEFAULT_MAX_STREAMS option, default 16, so the\nworst-case default preallocation is 128 MiB if the number of CPUs is no\nless than 16 while preserving the existing per-image dictionary limit.\nAn explicit lzma_streams module parameter is still honoured as-is, so\nadministrators who deliberately size the pool are not affected.","Type":"Description","Title":"erofs: cap LZMA stream pool size"}]}}}