CVE Database
/

CVE-2026-46078

Back to search

CVE-2026-46078

Published: May 27, 2026

Modified: Jun 1, 2026

PUBLISHED

CVSS v3.1

7.1

HIGH

Description

In the Linux kernel, the following vulnerability has been resolved: erofs: fix the out-of-bounds nameoff handling for trailing dirents Currently we already have boundary-checks for nameoffs, but the trailing dirents are special since the namelens are calculated with strnlen() with unchecked nameoffs. If a crafted EROFS has a trailing dirent with nameoff >= maxsize, maxsize - nameoff can underflow, causing strnlen() to read past the directory block. nameoff0 should also be verified to be a multiple of `sizeof(struct erofs_dirent)` as well [1]. [1] https://sashiko.dev/#/patchset/20260416063511.3173774-1-hsiangkao%40linux.alibaba.com

VendorProductVersions

Linux

Linux

affected
3aa8ec716e52c02360457fa018296629b4d0becf - < 80a23c6d1aba35be8746d74ac14e6ba5ae46da21
affected
3aa8ec716e52c02360457fa018296629b4d0becf - < 222055e6b4063abd2d9e13c3d49bbd1724c50789
affected
3aa8ec716e52c02360457fa018296629b4d0becf - < 48b27a955d22391c7f30169fa7b6b2e1977f1ce4
affected
3aa8ec716e52c02360457fa018296629b4d0becf - < 8ebb951a284b7446e025afc7dc5e9516ef9a7214
affected
3aa8ec716e52c02360457fa018296629b4d0becf - < 1d55445226c75ddd4e78b09b3e7d99109b28c366

+1 more versions

Linux

Linux

affected
4.19
unaffected
0 - < 4.19
unaffected
6.1.175 - <= 6.1.*
unaffected
6.6.140 - <= 6.6.*
unaffected
6.12.86 - <= 6.12.*

+3 more versions

CVSS v3.1 Details

CVSS v3.1 Vector

CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:H

Attack Vector

Local

Attack Complexity

Low

Privileges Required

None

User Interaction

Required

Scope

Unchanged

Confidentiality

High

Integrity

None

Availability

High

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now