← All Advisories

CVE-2026-97605

Last refreshed2026-10-03

Status: UPDATED  |  Advisory ID: CVE-2026-97605

Key Details

CVECVE-2026-97605
Affected productsLinux Linux

Affected Products, Subsystems & Sectors

VendorProductAffected VersionsPatch Status
LinuxLinux
SubsystemsGeneral OT
SectorsMultiple

What to Know

In the Linux kernel, the following vulnerability has been resolved:

erofs: preserve LZMA decoders on resize failure

The pool-resize path frees each stream's old decoder before allocating

its replacement. If an allocation fails after some streams have already

been replaced, the failed stream is put back on the list with state ==

NULL. z_erofs_lzma_max_dictsize is still advanced as if the whole

pool had been resized.

An existing LZMA mount can select the broken stream and pass

NULL to xz_dec_microlzma_reset(). A retry at the same size also

skip another resize attempt. Since the global maximum was advanced,

thus, the invalid state is left unrepaired.

Allocate each replacement before freeing the old decoder, temporarily

retaining one old decoder during allocation. Stop at the first failure

and advance z_erofs_lzma_max_dictsize only after all streams satisfy

the request.

Record each stream's dictionary capacity so retries can skip streams

already enlarged before a partial failure. (NVD)

What to Do

Monitor Linux's web page for any future patch releases.

References

SourceReference
NVDhttps://nvd.nist.gov/vuln/detail/CVE-2026-97605
CVEhttps://www.cve.org/CVERecord?id=CVE-2026-97605