{"id":"CVE-2026-64031","title":"erofs: fix managed cache race for unaligned extents","summary":"In the Linux kernel, the following vulnerability has been resolved:\n\nerofs: fix managed cache race for unaligned extents\n\nAfter unaligned compressed extents were introduced, the following race\ncould occur:\n\n[Thread 1]                    …","severity":"high","cvss":7.8,"cvssVector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","cvssSource":"cna","vendor":"Linux","product":"Linux","affected":["Linux >= 722f0fcdb0bb7d12a5c6d9460b9a7de1f735f36d < 2718cdb6db0fdbe375e61f2980aada27bafb323e","Linux >= 7361d1e3763baaf7b9349c576137851458ad38d1 < 425d32d6288d7d845e486af9419bbedccd8c9103","Linux >= 7361d1e3763baaf7b9349c576137851458ad38d1 < 038166f873c4caf6e85cfd4ea0c5a5ba297b4e8b","Linux >= 7361d1e3763baaf7b9349c576137851458ad38d1 < 649932fc3815eda2f24eb4de4b3a5e94886ee0b9","Linux 6.15"],"published":"2026-07-19","updated":"2026-09-14","sourceUpdated":"2026-09-14T11:58:35.405Z","source":"CVEORG","sourceUrl":"https://www.cve.org/CVERecord?id=CVE-2026-64031","references":[{"url":"https://git.kernel.org/stable/c/2718cdb6db0fdbe375e61f2980aada27bafb323e"},{"url":"https://git.kernel.org/stable/c/425d32d6288d7d845e486af9419bbedccd8c9103"},{"url":"https://git.kernel.org/stable/c/038166f873c4caf6e85cfd4ea0c5a5ba297b4e8b"},{"url":"https://git.kernel.org/stable/c/649932fc3815eda2f24eb4de4b3a5e94886ee0b9"}],"tags":["cve.org"],"epss":0.00129,"epssPercentile":0.02874,"ingestedAt":"2026-09-14T15:23:07.457Z","slug":"CVE-2026-64031","body":"## Overview\n\nIn the Linux kernel, the following vulnerability has been resolved:\n\nerofs: fix managed cache race for unaligned extents\n\nAfter unaligned compressed extents were introduced, the following race\ncould occur:\n\n[Thread 1]                                   [Thread 2]\n(z_erofs_fill_bio_vec)\n<handle a Z_EROFS_PREALLOCATED_FOLIO folio>\n...\nfilemap_add_folio (1)\n                                             (z_erofs_bind_cache)\n                                             <the same folio is found..>\n                                             ..\n                                             ..\nfolio_attach_private (2)\n                                             filemap_add_folio (3) again\n\nSince (1) is executed but (2) hasn't been executed yet, it's possible\nthat another thread finds the same managed folio in z_erofs_bind_cache()\nfor a different pcluster and calls filemap_add_folio() again since\nfolio->private is still Z_EROFS_PREALLOCATED_FOLIO.\n\nFix this by explicitly clearing folio->private before making the folio\nvisible in the managed cache so that another pcluster can simply wait\non the locked managed folio as what we did for other shared cases [1].\n\nThis only impacts unaligned data compression (`-E48bit` with zstd,\nfor example).\n\n[1] Commit 9e2f9d34dd12 (\"erofs: handle overlapped pclusters out of\n crafted images properly\") was originally introduced to handle crafted\n overlapped extents, but it addresses unaligned extents as well.\n\n## Affected\n\n- `Linux >= 722f0fcdb0bb7d12a5c6d9460b9a7de1f735f36d < 2718cdb6db0fdbe375e61f2980aada27bafb323e`\n- `Linux >= 7361d1e3763baaf7b9349c576137851458ad38d1 < 425d32d6288d7d845e486af9419bbedccd8c9103`\n- `Linux >= 7361d1e3763baaf7b9349c576137851458ad38d1 < 038166f873c4caf6e85cfd4ea0c5a5ba297b4e8b`\n- `Linux >= 7361d1e3763baaf7b9349c576137851458ad38d1 < 649932fc3815eda2f24eb4de4b3a5e94886ee0b9`\n- `Linux 6.15`\n\n## Remediation\n\nRefer to the linked advisories for vendor-supplied fixes and affected version ranges.","depth":"twilight","depthScore":43,"depthScoreParts":{"impact":42.9,"likelihood":0,"exploitation":0,"ransomware":0},"changes":[]}