๐Ÿ” CVE Alert

CVE-2026-64146

UNKNOWN 0.0

erofs: fix metabuf leak in inode xattr initialization

CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th

In the Linux kernel, the following vulnerability has been resolved: erofs: fix metabuf leak in inode xattr initialization commit bb88e8da0025 ("erofs: use meta buffers for xattr operations") converted xattr operations to use on-stack erofs_buf instances. erofs_init_inode_xattrs() uses such a metabuf while reading the inline xattr header and shared xattr id array. Some error paths after erofs_read_metabuf() leave through out_unlock without dropping the metabuf, so the folio reference can leak. Consolidate the cleanup at out_unlock. erofs_put_metabuf() is a no-op if no folio has been acquired, and this keeps all paths after taking EROFS_I_BL_XATTR_BIT covered by a single cleanup site.

Vendor linux
Product linux
Ecosystems
Industries
Technology
Published Jul 19, 2026
Stay Ahead of the Next One

Get instant alerts for linux linux

Be the first to know when new unknown vulnerabilities affecting linux linux are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

Affected Versions

Linux / Linux
bb88e8da00253bea0e7f0f4cdfd7910572d7799f < 492c73b21fefa36f3869cb2b188ffb7fe37b3a9b bb88e8da00253bea0e7f0f4cdfd7910572d7799f < 79b09c54c6563df9846ca3094bcfd72082c3e1d7
Linux / Linux
5.17

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
git.kernel.org: https://git.kernel.org/stable/c/492c73b21fefa36f3869cb2b188ffb7fe37b3a9b git.kernel.org: https://git.kernel.org/stable/c/79b09c54c6563df9846ca3094bcfd72082c3e1d7