---
id: CVE-2026-53015
title: |-
  In the Linux kernel, the following vulnerability has been resolved:

  erofs: unify lcn as u64 for 32-bit platforms

  As sashiko reported [1], `lcn` was typed as `unsigned long` (or
  `unsigned int` sometimes), which is only 32 bits wide on 3…
summary: |-
  In the Linux kernel, the following vulnerability has been resolved:

  erofs: unify lcn as u64 for 32-bit platforms

  As sashiko reported [1], `lcn` was typed as `unsigned long` (or
  `unsigned int` sometimes), which is only 32 bits wide on 3…
severity: none
published: '2026-06-24'
updated: '2026-07-10'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-53015'
references:
  - url: 'https://git.kernel.org/stable/c/2d8c7edcb661812249469f4a5b62e9339118846f'
    label: 416baaa9-dc9f-4396-8d5f-8c081fb06d67
  - url: 'https://git.kernel.org/stable/c/4fc9b12e43a3f19a01a8fb61f7961be79de20253'
    label: 416baaa9-dc9f-4396-8d5f-8c081fb06d67
  - url: 'https://git.kernel.org/stable/c/582b0bf201157632cb5474c885989a6ebda46521'
    label: 416baaa9-dc9f-4396-8d5f-8c081fb06d67
  - url: 'https://git.kernel.org/stable/c/858e4d98a86adf34584767388deb6c9b217f70c5'
    label: 416baaa9-dc9f-4396-8d5f-8c081fb06d67
tags:
  - nvd
epss: 0.00122
epssPercentile: 0.02276
ingestedAt: '2026-07-11T19:15:11.776Z'
---

## Overview

In the Linux kernel, the following vulnerability has been resolved:

erofs: unify lcn as u64 for 32-bit platforms

As sashiko reported [1], `lcn` was typed as `unsigned long` (or
`unsigned int` sometimes), which is only 32 bits wide on 32-bit
platforms, which causes `(lcn << lclusterbits)` to be truncated
at 4 GiB.

In order to consolidate the logic, just use `u64` consistently
around the codebase.

[1] https://sashiko.dev/r/20260420034612.1899973-1-hsiangkao%40linux.alibaba.com

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
