Vulnerability Description
In the Linux kernel, the following vulnerability has been resolved: erofs: fix interlaced ztailpacking pclusters On-disk sizes of interlaced pclusters should be block-aligned, and ztailpacking interlaced pclusters should be invalid at all. Currently, mkfs.erofs won't generate any interlaced pcluster with ztailpacking enabled, so this doesn't affect any existing valid filesystems. However, crafted images can contain invalid interlaced ztailpacking pclusters, resulting in an out-of-bounds read from a kmap'd page and copying irrelevant kernel memory into userspace-visible page cache.
CVSS Score
HIGH
References
- https://git.kernel.org/stable/c/451027c642e752420e1a04237db9ce7b35cee595
- https://git.kernel.org/stable/c/862427ebb81d1f6abbf74d799790e1694b37b187
- https://git.kernel.org/stable/c/ddb7ea4fd99bf6c4314d1dfca18aec6945ce8054
FAQ
What is CVE-2026-90161?
CVE-2026-90161 is a vulnerability with a CVSS score of 7.1 (HIGH). In the Linux kernel, the following vulnerability has been resolved: erofs: fix interlaced ztailpacking pclusters On-disk sizes of interlaced pclusters should be block-aligned, and ztailpacking inter...
How severe is CVE-2026-90161?
CVE-2026-90161 has been rated HIGH with a CVSS base score of 7.1/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2026-90161?
Check the references section above for vendor advisories and patch information. Review vendor security bulletins for remediation guidance.