CVE-2026-46078
In the Linux kernel, the following vulnerability has been resolved: erofs: fix the out-of-bounds nameoff handling for trailing dirents Currently we already have boundary-checks for nameoffs, but the trailing dirents are special since the namelens are calculated with strnlen() with unchecked nameoffs. If a crafted EROFS has a trailing dirent with nameoff >= maxsize, maxsize - nameoff can underflow, causing strnlen() to read past the directory block. nameoff0 should also be verified to be a multiple of `sizeof(struct erofs_dirent)` as well [1]. [1] https://sashiko.dev/#/patchset/20260416063511.3173774-1-hsiangkao%40linux.alibaba.com
वीकनेस
In the Linux kernel, the following vulnerability has been resolved: erofs: fix the out-of-bounds nameoff handling for trailing dirents Currently we already have boundary-checks for nameoffs, but the trailing dirents are special since the namelens are calculated with strnlen() with unchecked nameoffs. If a crafted EROFS has a trailing dirent with nameoff >= maxsize, maxsize - nameoff can underflow, causing strnlen() to read past the directory block. nameoff0 should also be verified to be a multiple of `sizeof(struct erofs_dirent)` as well [1]. [1] https://sashiko.dev/#/patchset/20260416063511.3173774-1-hsiangkao%40linux.alibaba.com
प्रभावित प्रोडक्ट
- linux linux_kernel
संदर्भ
- https://git.kernel.org/stable/c/1d55445226c75ddd4e78b09b3e7d99109b28c366
- https://git.kernel.org/stable/c/222055e6b4063abd2d9e13c3d49bbd1724c50789
- https://git.kernel.org/stable/c/48b27a955d22391c7f30169fa7b6b2e1977f1ce4
- https://git.kernel.org/stable/c/80a23c6d1aba35be8746d74ac14e6ba5ae46da21
- https://git.kernel.org/stable/c/8ebb951a284b7446e025afc7dc5e9516ef9a7214
- https://git.kernel.org/stable/c/a8ee527807f7d97e55ce2ef2906f7f34975eb1c7
हमलावर से पहले बग आप ढूँढें।
GitHub से साइन इन करें और एक मिनट से भी कम में अपना पहला ऑडिट चलाएँ। फ़्री प्लान के लिए क्रेडिट कार्ड की ज़रूरत नहीं।