Out-of-bounds read in Linux kernel - CVE-2026-43166
Published: May 7, 2026
Linux kernel
Detailed vulnerability description
The vulnerability allows a local user to disclose sensitive information.
The vulnerability exists due to an out-of-bounds read in z_erofs_transform_plain() when processing a crafted compressed image containing plain extents with unaligned physical lengths. A local user can supply a specially crafted compressed image to disclose sensitive information.