Memory Leak Vulnerability in Linux Kernel EROFS
CVE-2026-64146
Currently unrated
What is CVE-2026-64146?
A memory leak vulnerability exists in the Linux kernel's EROFS (Enhanced Read-Only File System) where certain error paths do not properly release metabolization buffers during the initialization of inode extended attributes (xattrs). This oversight can result in leaked references to folios when the cleanup procedure is not consistently triggered, leading to resource exhaustion. Proper consolidation of the cleanup mechanism is required to address the issue and ensure all scenarios are accounted for.
Affected Version(s)
Linux bb88e8da00253bea0e7f0f4cdfd7910572d7799f < 492c73b21fefa36f3869cb2b188ffb7fe37b3a9b
Linux bb88e8da00253bea0e7f0f4cdfd7910572d7799f < 79b09c54c6563df9846ca3094bcfd72082c3e1d7
Linux 5.17