In the Linux kernel, the following vulnerability has been resolved:
erofs: fix memory leak of LZMA global compressed deduplication
When stressing microLZMA EROFS images with the new global compressed deduplication feature enabled (`-Ededupe`), I found some short-lived temporary pages weren't properly released, which could slowly cause unexpected OOMs hours later.
Let's fix it now (LZ4 and DEFLATE don't have this issue.)
CVSS Details
- CVSS 3.1 Base Score: 5.5
- CVSS 3.1 Vector: (CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Debian | — | Upgrade linux | Jul 30, 2024 | Mar 2, 2024 |
| Ubuntu | — | Upgrade linux-lowlatencyUpgrade linux-oracleUpgrade linux-oem-6.5Upgrade linux-raspiUpgrade linux-riscvUpgrade linux-starfiveUpgrade linux-gcpUpgrade linux-oracle-6.5Upgrade linuxUpgrade linux-gcp-6.5Upgrade linux-awsUpgrade linux-lowlatency-hwe-6.5Upgrade linux-hwe-6.5Upgrade linux-laptopUpgrade linux-nvidia-6.5 | Nov 19, 2024 | Mar 2, 2024 |
| Vmware Photon_os | — | Use 'tdnf update' to upgrade all packages to the latest version. | Oct 14, 2025 | Mar 2, 2024 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub