Linux Kernel Vulnerability in ERoFS Impacting Kernel Performance
CVE-2026-80697
What is CVE-2026-80697?
A vulnerability in the Linux kernel's ERoFS component can lead to a critical null pointer dereference due to improper handling of file paths during page cache sharing. Specifically, the backing files for page cache were previously initialized with an invalid f_path, which can cause a crash when specific conditions are met. This issue was traced back to interactions with a recent mincore fix, leading to crashes in kernel mode. The resolution involves ensuring that valid paths are specified using proper disconnected dentries, thus allowing for better stability in memory handling and cache sharing processes.
Affected Version(s)
Linux 04ba248d02d9eaa3d9077b00a6134caa75fa3e90 < 3879657c4ffd81b9a42cf575fc6cb60201032587
Linux e187bc02f8fa4226d62814592cf064ee4557c470 < 96b2dbbe58a1ea5df8d29c2fe24b5f04715f4443
Linux 7368bec565bac3e536cd43579dbde1e715e6ba61