๐Ÿ” CVE Alert

CVE-2026-46078

HIGH 7.1

erofs: fix the out-of-bounds nameoff handling for trailing dirents

CVSS Score
7.1
EPSS Score
0.0%
EPSS Percentile
0th

In the Linux kernel, the following vulnerability has been resolved: erofs: fix the out-of-bounds nameoff handling for trailing dirents Currently we already have boundary-checks for nameoffs, but the trailing dirents are special since the namelens are calculated with strnlen() with unchecked nameoffs. If a crafted EROFS has a trailing dirent with nameoff >= maxsize, maxsize - nameoff can underflow, causing strnlen() to read past the directory block. nameoff0 should also be verified to be a multiple of `sizeof(struct erofs_dirent)` as well [1]. [1] https://sashiko.dev/#/patchset/20260416063511.3173774-1-hsiangkao%40linux.alibaba.com

Vendor linux
Product linux
Ecosystems
Industries
Technology
Published May 27, 2026
Last Updated Jun 1, 2026
Stay Ahead of the Next One

Get instant alerts for linux linux

Be the first to know when new high vulnerabilities affecting linux linux are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

CVSS v3 Breakdown

CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:H
Attack Vector
Attack Complexity
Privileges Required
User Interaction
Scope
Confidentiality
Integrity
Availability

Affected Versions

Linux / Linux
3aa8ec716e52c02360457fa018296629b4d0becf < 80a23c6d1aba35be8746d74ac14e6ba5ae46da21 3aa8ec716e52c02360457fa018296629b4d0becf < 222055e6b4063abd2d9e13c3d49bbd1724c50789 3aa8ec716e52c02360457fa018296629b4d0becf < 48b27a955d22391c7f30169fa7b6b2e1977f1ce4 3aa8ec716e52c02360457fa018296629b4d0becf < 8ebb951a284b7446e025afc7dc5e9516ef9a7214 3aa8ec716e52c02360457fa018296629b4d0becf < 1d55445226c75ddd4e78b09b3e7d99109b28c366 3aa8ec716e52c02360457fa018296629b4d0becf < d18a3b5d337fa412a38e776e6b4b857a58836575
Linux / Linux
4.19

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
git.kernel.org: https://git.kernel.org/stable/c/80a23c6d1aba35be8746d74ac14e6ba5ae46da21 git.kernel.org: https://git.kernel.org/stable/c/222055e6b4063abd2d9e13c3d49bbd1724c50789 git.kernel.org: https://git.kernel.org/stable/c/48b27a955d22391c7f30169fa7b6b2e1977f1ce4 git.kernel.org: https://git.kernel.org/stable/c/8ebb951a284b7446e025afc7dc5e9516ef9a7214 git.kernel.org: https://git.kernel.org/stable/c/1d55445226c75ddd4e78b09b3e7d99109b28c366 git.kernel.org: https://git.kernel.org/stable/c/d18a3b5d337fa412a38e776e6b4b857a58836575