CVE-2026-89602

Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
11/09/2026
Last modified:
21/09/2026

Description

In the Linux kernel, the following vulnerability has been resolved:<br /> <br /> erofs: skip sufficiently large global buffers when resizing<br /> <br /> z_erofs_gbuf_nrpages is advanced only after every global buffer has been<br /> grown. If a resize fails after some buffers were enlarged, a retry<br /> revisits those enlarged buffers.<br /> <br /> Retrying the same size then returns -ENOMEM because alloc_pages_bulk()<br /> has no pages to add and the unchanged return value is treated as a<br /> failure. Retrying an intermediate size allocates a temporary pointer<br /> array smaller than gbuf-&gt;nrpages and copies more existing pointers than<br /> the array can hold.<br /> <br /> Skip buffers that already satisfy the request. Once all remaining<br /> buffers have caught up, advancing z_erofs_gbuf_nrpages again describes<br /> the guaranteed minimum size across the pool.