Linux Kernel EROFS Uncompressed Pcluster Length Validation Vulnerability

Vulnerability

A use-after-free vulnerability has been identified in the Linux kernel's EROFS (Enhanced Read-Only File System) component. This issue arises from improper validation of extent lengths for uncompressed pclusters, which can lead to memory corruption. The vulnerability was reported by syzkaller and is associated with a fuzzed image that revealed two problems: a non-inlined pcluster with a physical address of zero, and a logical length that exceeds the physical length. While the first issue has been addressed, this vulnerability remains due to the lack of proper extent length validation.

Impact

Exploitation of this vulnerability can lead to a use-after-free condition, causing memory corruption.

Remediation

Users can upgrade to the latest version of the Linux kernel where this vulnerability has been addressed. Instructions for downloading the patched version are available on the official Linux kernel website.

Added: Dec 24, 2025, 5:21 PM
Updated: Dec 24, 2025, 5:21 PM

Vulnerability Rating

Custom Algorithm
spread
9.0
impact
2.5
exploitability
5.3
remediation
7.7
relevance
1.6
threat
3.2
urgency
2.9
incentive
1.7

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.