Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

CVE-2026-46329— erofs: handle end of filesystem properly for file-backed mounts

Quick assessment

Affected
Linux Linux
Exploitation
No confirmed in-the-wild exploitation; assess based on exposure
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

Linux kernel是美国Linux基金会的开源操作系统Linux所使用的内核。 Linux kernel存在安全漏洞,该漏洞源于erofs文件系统对文件后端挂载的边界处理不当,可能导致超出文件系统末尾的I/O请求未被正确清零。

AI Predicted 5.5 Difficulty: Moderate EPSS 0.11% · P2

Possible ATT&CK Techniques 1 AI

T1068 · Exploitation for Privilege Escalation

Affected Version Matrix 10

VendorProduct Version RangeStatus
Linux Linux ce63cb62d794c98c7631c2296fa845f2a8d0a4a1< 8d582d65d20bb4796db01b19e86909ad68cb337b affected
ce63cb62d794c98c7631c2296fa845f2a8d0a4a1< e49abde0ffc382a967b24f326d1614ac3bb06a94 affected
ce63cb62d794c98c7631c2296fa845f2a8d0a4a1< fe4039034dcdf584afbf763787909e28e92a4927 affected
ce63cb62d794c98c7631c2296fa845f2a8d0a4a1< bc804a8d7e865ef47fb7edcaf5e77d18bf444ebc affected
6.12 affected
< 6.12 unaffected
6.12.75≤ 6.12.* unaffected
6.18.14≤ 6.18.* unaffected
… +2 more rows
Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2026-46329

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
erofs: handle end of filesystem properly for file-backed mounts
Source: CVE Program / CVE List V5
Vulnerability Description
In the Linux kernel, the following vulnerability has been resolved: erofs: handle end of filesystem properly for file-backed mounts I/O requests beyond the end of the filesystem should be zeroed out, similar to loopback devices and that is what we expect.
Source: CVE Program / CVE List V5
CVSS Information
N/A
Source: CVE Program / CVE List V5
Vulnerability Type
N/A
Source: CVE Program / CVE List V5
Vulnerability Title
Linux kernel 安全漏洞
Source: CNNVD (China National Vulnerability Database)
Vulnerability Description
Linux kernel是美国Linux基金会的开源操作系统Linux所使用的内核。 Linux kernel存在安全漏洞,该漏洞源于erofs文件系统对文件后端挂载的边界处理不当,可能导致超出文件系统末尾的I/O请求未被正确清零。
Source: CNNVD (China National Vulnerability Database)
CVSS Information
N/A
Source: CNNVD (China National Vulnerability Database)
Vulnerability Type
N/A
Source: CNNVD (China National Vulnerability Database)

Affected Products

Vendor Product Affected Versions CPE Subscribe
Linux Linux ce63cb62d794c98c7631c2296fa845f2a8d0a4a1 ~ 8d582d65d20bb4796db01b19e86909ad68cb337b -
Linux Linux 6.12 -

II. Public POCs for CVE-2026-46329

# POC Description Source Link Shenlong Link
AI-Generated POC Premium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2026-46329

登录查看更多情报信息。

Patches & Fixes for CVE-2026-46329 (4)

Same Patch Batch · Linux · 2026-06-09 · 21 CVEs total

CVE-2026-46325 9.8 CRITICAL RDMA/rxe: Fix iova-to-va conversion for MR page sizes != PAGE_SIZE
CVE-2026-46316 9.3 CRITICAL KVM: arm64: vgic-its: Drop the translation cache reference only for the erased entry
CVE-2026-46317 8.8 HIGH KVM: arm64: Reassign nested_mmus array behind mmu_lock
CVE-2026-46326 8.4 HIGH iio: pressure: mprls0025pa: fix spi_transfer struct initialisation
CVE-2026-46332 8.0 HIGH greybus: gb-beagleplay: bound bootloader receive buffering
CVE-2026-52907 7.8 HIGH media: rockchip: rkcif: fix off by one bugs
CVE-2026-46330 7.8 HIGH Revert "net/smc: Introduce TCP ULP support"
CVE-2026-46319 7.8 HIGH net/sched: act_ct: Only release RCU read lock after ct_ft
CVE-2026-46327 7.8 HIGH dm: fix unlocked test for dm_suspended_md
CVE-2026-46324 7.8 HIGH netfilter: nf_tables: use list_del_rcu for netlink hooks
CVE-2026-46323 7.8 HIGH net: gro: don't merge zcopy skbs
CVE-2026-52906 7.7 HIGH 9p: fix access mode flags being ORed instead of replaced
CVE-2026-46320 7.4 HIGH tap: free page on error paths in tap_get_user_xdp()
CVE-2026-46328 7.3 HIGH apparmor: fix rlimit for posix cpu timers
CVE-2026-46322 7.1 HIGH tun: free page on build_skb failure in tun_xdp_one()
CVE-2026-46321 7.1 HIGH tun: free page on short-frame rejection in tun_xdp_one()
CVE-2026-46318 Revert "mm/hugetlbfs: update hugetlbfs to use mmap_prepare"
CVE-2026-52904 drm/nouveau: fix nvkm_device leak on aperture removal failure
CVE-2026-52905 mm/damon/core: disallow non-power of two min_region_sz on damon_start()
CVE-2026-46315 io_uring/waitid: clear waitid info before copying it to userspace

IV. Related Vulnerabilities

V. Comments for CVE-2026-46329

No comments yet


Leave a comment