CVE-2024-26590: erofs: fix inconsistent per-file compression format
In the Linux kernel, the following vulnerability has been resolved:
erofs: fix inconsistent per-file compression format
EROFS can select compression algorithms on a per-file basis, and each
per-file compression algorithm needs to be marked in the on-disk
superblock for initialization.
However, syzkaller can generate inconsistent crafted images that use
an unsupported algorithmtype for specific inodes, e.g. use MicroLZMA
algorithmtype even it's not set in `sbi->available_compr_algs`. This
can lead to an unexpected "BUG: kernel NULL pointer dereference" if
the corresponding decompressor isn't built-in.
Fix this by checking against `sbi->available_compr_algs` for each
m_algorithmformat request. Incorrect !erofs_sb_has_compr_cfgs preset
bitmap is now fixed together since it was harmless previously.
Security readout for executives and security teams
Plain-English summary
CVE-2024-26590 can crash a Linux system when a crafted EROFS filesystem image requests an unsupported per-file compression algorithm. The impact is denial of service, not data theft or code execution, based on the provided sources.
Executive priority
Treat this as a moderate availability risk. Prioritize shared Linux hosts, container platforms, CI systems, and appliances that process filesystem images. It is not described as remote compromise.
Technical view
The Linux EROFS code failed to validate per-inode compression format requests against the superblock’s available compression algorithms. A crafted image could trigger a NULL pointer dereference when the decompressor was not built in. The fix adds validation against available_compr_algs.
Likely exposure
Exposure is most relevant where local users, containers, build systems, forensic tools, or appliances can mount or process untrusted EROFS images. Systems that never handle EROFS images are less likely to be exposed.
Exploitation context
The CVSS vector is local, low complexity, low privileges, no user interaction, with high availability impact. The source bundle does not show CISA KEV listing or cited evidence of active exploitation.
Researcher notes
Evidence supports a crafted-image denial-of-service condition in Linux EROFS. The provided affected-version data is limited and should be reconciled against distro kernel advisories and commit backports before declaring systems fixed.
Mitigation direction
Apply a vendor kernel update containing the referenced Linux stable fixes.
Check distribution advisories for backported fixes to supported kernels.
Restrict local users and workloads from mounting untrusted filesystem images.
Reduce or disable EROFS usage where it is not operationally required.
Prioritize hardened mount policies for containers and build hosts.
Validation and detection
Inventory Linux kernel versions on systems that use or mount EROFS.
Confirm whether vendor kernels include the referenced stable commits or backports.
Review whether untrusted users or workloads can provide filesystem images.
Check EROFS-related kernel configuration and module exposure.
Validate that monitoring covers kernel oops or panic events.
Generated from the cited source records. This long-tail analysis has not been individually reviewed by a named human.
Potential ATT&CK relevance
Conservative CVE-to-ATT&CK context
These mappings and lookup hints may be relevant to the vulnerability behavior, CWE, affected product, or exposure path. Glexia-inferred context is not an official MITRE, ATT&CK, CWE, or CVE Program mapping.
ATT&CK lookup starting points
Use these exact CWE pages and searches to review the Glexia ATT&CK library from this CVE's weakness and description context.
cwe · low confidence lookup
CWE-476: Exact CWE lookup
Use the exact CWE identifier as the starting point before reviewing related ATT&CK behavior. Open the exact CWE lookup page first, then review the ATT&CK searches from that MITRE weakness context. This is a Glexia lookup hint, not an official ATT&CK mapping.
These fields come from the CVE record and ADP containers, not from Glexia's Take. They preserve time-varying source decisions such as CISA SSVC, KEV status, CVSS metrics, and provider references.
We collect every scored CVSS vector available in the official CNA and ADP containers. When more than one version is present, the table keeps the source vectors side by side instead of collapsing them into the highest score.
CWE links open Glexia weakness intelligence pages with official CWE context, developer remediation guidance, and related CVE mappings.
CWE-476 · source CWE mapping
NULL Pointer Dereference
NULL Pointer Dereference represents a recurring weakness pattern that can create exploitable paths when design, validation, or implementation controls are missing.