CVE-2026-43154 Details
Description
In the Linux kernel, the following vulnerability has been resolved: erofs: fix incorrect early exits in volume label handling Crafted EROFS images containing valid volume labels can trigger incorrect early returns, leading to folio reference leaks. However, this does not cause system crashes or other severe issues.
A vulnerability in the Linux kernel's EROFS (Enhanced Read-Only File System) implementation can lead to folio reference leaks. This issue arises from incorrect early exits in volume label handling, which can be triggered by crafted EROFS images containing valid volume labels. While this vulnerability causes a reference leak, it does not result in system crashes or other severe problems.
Users can upgrade to the latest version of the Linux kernel where this vulnerability has been addressed. The specific commit that resolves this issue is 3afa4da38802a4cba1c23848a32284e7e57b831b.
Metrics
CVSS 4.0 Severity and Vector Strings:
No CVSS 4.0 data is available for this CVE.
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
No SSVC data is available for this CVE.
References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://git.kernel.org/stable/c/3afa4da38802a4cba1c23848a32284e7e57b831b | kernel.org | Patch |
| https://git.kernel.org/stable/c/8d8a878ef60801d867119b3df6a93e2982d62a71 | kernel.org | Patch |
| https://git.kernel.org/stable/c/d498bd168494ad4a4bce16192bfb9ce04ca19c9a | kernel.org | Patch |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| NVD-CWE-noinfo | Insufficient Information to Classify Weakness | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| linux linux kernel | >= 6.18, < 6.18.16 >= 6.19, < 6.19.6 |
CPE
Remediation
| |
Change History
3 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | kernel.org |
| May 13, 2026 | Initial Analysis | [email protected] |
| May 6, 2026 | New CVE Received | kernel.org |