Expected behavior violation in Linux kernel - CVE-2026-98067
Published: September 28, 2026
Vulnerability details
The vulnerability allows a local user to cause data corruption.
The vulnerability exists due to an incorrect assumption about LZ4 literal copy direction in EROFS LZ4 rolling decompression when processing LZ4-compressed extents. A local user can trigger decompression of an LZ4-compressed extent to cause data corruption.
The issue can occur on x86 because the upstream LZ4 literal-copy memmove() may copy non-overlapping long literals backward.