NULL pointer dereference in Linux kernel - CVE-2026-97605
Published: September 28, 2026
Vulnerability details
The vulnerability allows a local user to cause a denial of service.
The vulnerability exists due to improper handling of failed LZMA decoder allocations in the EROFS LZMA decoder pool resize path when resizing decoder pools. A local user can trigger a decoder-pool resize that encounters an allocation failure to cause a denial of service.
An existing LZMA mount is required.