Linux Kernel EROFS Vulnerability in Nydus Product
CVE-2026-80899

Currently unrated

Key Information:

Vendor

Linux

Status
Vendor
CVE Published:
4 September 2026

What is CVE-2026-80899?

A vulnerability in the Linux kernel involves the deprecation of the fscache backend for the EROFS file system. Initially introduced to facilitate image lazy pulling, the feature created an unexpected dependency on the netfs subsystem, complicating local file system operations. Due to the existence of alternatives, namely fanotify pre-content hooks which provide equivalent functionality, the fscache backend has been removed. This decision not only simplifies the codebase but also aligns with Nydus's transition towards utilizing fanotify for enhanced reliability. This change aims to streamline EROFS functionality while addressing previously noted implementation issues.

Affected Version(s)

Linux 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2

Linux 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2

Linux 0 < 7.1.8

References

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.