CVE-2026-89602
Received Received - Intake

Integer Overflow in EROFS Filesystem Resizing

Vulnerability report for CVE-2026-89602, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-09-11

Last updated on: 2026-09-21

Assigner: kernel.org

Description

In the Linux kernel, the following vulnerability has been resolved: erofs: skip sufficiently large global buffers when resizing z_erofs_gbuf_nrpages is advanced only after every global buffer has been grown. If a resize fails after some buffers were enlarged, a retry revisits those enlarged buffers. Retrying the same size then returns -ENOMEM because alloc_pages_bulk() has no pages to add and the unchanged return value is treated as a failure. Retrying an intermediate size allocates a temporary pointer array smaller than gbuf->nrpages and copies more existing pointers than the array can hold. Skip buffers that already satisfy the request. Once all remaining buffers have caught up, advancing z_erofs_gbuf_nrpages again describes the guaranteed minimum size across the pool.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-09-11
Last Modified
2026-09-21
Generated
2026-10-02
AI Q&A
2026-09-12
EPSS Evaluated
2026-09-30
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
linux linux_kernel *

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-UNKNOWN

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This is a Linux kernel vulnerability where a resize operation on global buffers may fail due to incorrect handling of already enlarged buffers. When retrying the resize, the system may run out of memory or attempt to copy more pointers than available space, leading to errors.

Detection Guidance

This vulnerability is specific to the Linux kernel's erofs filesystem and does not have a direct detection method via network or system commands. It requires kernel code analysis or monitoring for filesystem resize failures. Check kernel logs for erofs-related errors or failures during buffer resizing operations.

Impact Analysis

This vulnerability could cause system instability or crashes during file system operations involving erofs. It may lead to out-of-memory errors or corruption if resize operations fail repeatedly.

Compliance Impact

This vulnerability is specific to the Linux kernel's EROFS filesystem and does not directly impact compliance with standards like GDPR or HIPAA. It involves a memory allocation issue during filesystem resizing, which could lead to system instability or crashes but does not inherently affect data protection or privacy controls required by these regulations.

Mitigation Strategies

Update your Linux kernel to the latest patched version that resolves this issue. Monitor kernel logs for erofs resize failures and apply patches promptly. If using a vulnerable kernel, avoid operations that trigger erofs buffer resizing until patched.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-89602. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart