🛡️ CVE-2026-45943 — kernel

🟠 CVSS 7.1 — High ✅ No Known Exploit NVD
7.1
CVSS Score
0 Low4 Medium7 High9 Critical10

Description

erofs: fix inline data read failure for ztailpacking pclusters

In the Linux kernel, the following vulnerability has been resolved:

erofs: fix inline data read failure for ztailpacking pclusters

Compressed folios for ztailpacking pclusters must be valid before adding

these pclusters to I/O chains. Otherwise, z_erofs_decompress_pcluster()

may assume they are already valid and then trigger a NULL pointer

dereference.

It is somewhat hard to reproduce because the inline data is in the same

block as the tail of the compressed indexes, which are usually read just

before. However, it may still happen if a fatal signal arrives while

read_mapping_folio() is running, as shown below:

erofs: (device dm-1): z_erofs_pcluster_begin: failed to get inline data -4

Unable to handle kernel NULL pointer dereference at virtual address 0000000000000008

...

pc : z_erofs_decompress_queue+0x4c8/0xa14

lr : z_erofs_decompress_queue+0x160/0xa14

sp : ffffffc08b3eb3a0

x29: ffffffc08b3eb570 x28: ffffffc08b3eb418 x27: 0000000000001000

x26: ffffff8086ebdbb8 x25: ffffff8086ebdbb8 x24: 0000000000000001

x23: 0000000000000008 x22: 00000000fffffffb x21: dead000000000700

x20: 00000000000015e7 x19: ffffff808babb400 x18: ffffffc089edc098

x17: 00000000c006287d x16: 00000000c006287d x15: 0000000000000004

x14: ffffff80ba8f8000 x13: 0000000000000004 x12: 00000006589a77c9

x11: 0000000000000015 x10: 0000000000000000 x9 : 0000000000000000

x8 : 0000000000000000 x7 : 0000000000000000 x6 : 000000000000003f

x5 : 0000000000000040 x4 : ffffffffffffffe0 x3 : 0000000000000020

x2 : 0000000000000008 x1 : 0000000000000000 x0 : 0000000000000000

Call trace:

z_erofs_decompress_queue+0x4c8/0xa14

z_erofs_runqueue+0x908/0x97c

z_erofs_read_folio+0x128/0x228

filemap_read_folio+0x68/0x128

filemap_get_pages+0x44c/0x8b4

filemap_read+0x12c/0x5b8

generic_file_read_iter+0x4c/0x15c

do_iter_readv_writev+0x188/0x1e0

vfs_iter_read+0xac/0x1a4

backing_file_read_iter+0x170/0x34c

ovl_read_iter+0xf0/0x140

vfs_read+0x28c/0x344

ksys_read+0x80/0xf0

__arm64_sys_read+0x24/0x34

invoke_syscall+0x60/0x114

el0_svc_common+0x88/0xe4

do_el0_svc+0x24/0x30

el0_svc+0x40/0xa8

el0t_64_sync_handler+0x70/0xbc

el0t_64_sync+0x1bc/0x1c0

Fix this by reading the inline data before allocating and adding

the pclusters to the I/O chains.

How this vulnerability can be exploited

This issue can be reached with local access to the system, attack complexity is low, an attacker needs low-level privileges on the target. No user interaction is required. The scope is unchanged, so the impact stays within the vulnerable component. Rated impact: confidentiality high, integrity none, availability high.

Affected software

CVE-2026-45943 is recorded against 3 packages.

  • kernel (from 6.19.0 up to 6.19.4)
  • linux-kernel (from 6.19 up to 6.19.4)
  • unknown

Timeline and source

Published on 27 May 2026 and last revised on 15 July 2026. No public exploit is currently recorded for this entry. A vendor advisory or fix has been published. Record sourced from NVD.

References

git.kernel.org (Web)
git.kernel.org (Web)
git.kernel.org (Web)
git.kernel.org (Web)
github.com (Advisory)
nvd.nist.gov (Advisory)
git.kernel.org (Package)

CVE-2026-45943 on other distributions

Each distribution ships its own build and its own fixed version. Pick the one you run:

Details

Severity High
CVSS Score 7.1
CVSS Vector CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H
CWE N/A
Public Exploit ✅ No
Source NVD
Published 2026-05-27
Updated 2026-08-12
Modified 2026-07-15

Affected Packages

Software From version Fixed in
kernel 6.19.0 6.19.4
linux-kernel 6.19 6.19.4
unknown

Similar Threats

Site Security Check

Is kernel part of your stack?

CVE-2026-45943 is rated CVSS 7.1 High. BotEraser scans your installation against known CVE records and tells you whether this vulnerability applies to the versions you actually run.

Scan My Site Free →

No credit card required  ·  Results in minutes

ⓘ Data Notice: The information presented above has been compiled from publicly available internet sources. Boteraser aggregates this data solely for informational purposes and does not independently classify, evaluate, or endorse any findings about the vulnerabilities listed. The accuracy and completeness of this information is the sole responsibility of the original publishers. Boteraser and its operators accept no liability for any decisions made based on this data.