MEDIUM

CVE-2026-53015

Linux Linux Kernel 2026-06-24 CVSS v3.1
CVSS
5.5

Description

In the Linux kernel, the following vulnerability has been resolved:

erofs: unify lcn as u64 for 32-bit platforms

As sashiko reported [1], `lcn` was typed as `unsigned long` (or
`unsigned int` sometimes), which is only 32 bits wide on 32-bit
platforms, which causes `(lcn << lclusterbits)` to be truncated
at 4 GiB.

In order to consolidate the logic, just use `u64` consistently
around the codebase.

[1] https://sashiko.dev/r/20260420034612.1899973-1-hsiangkao%40linux.alibaba.com

Summary dbcve.org

In the Linux kernel's erofs filesystem, the logical cluster number (lcn) variable was incorrectly typed as `unsigned long` or `unsigned int`, which is only 32 bits wide on 32-bit platforms. When performing `(lcn << lclusterbits)` to calculate cluster offsets, the result gets truncated at 4 GiB, potentially causing incorrect data access or file system corruption when handling files/clusters beyond 4 GiB on 32-bit systems.

Mitigation

This is a kernel bug fix requiring a type change from 32-bit to 64-bit (u64). No end-user mitigation is available; organizations should apply kernel updates when available.

Patch Commit

EPSS Score

0.12%
Probability of exploitation in next 30 days
2.3th percentile

References

View on dbcve.org
Base CVE data derived from NVD (public domain). Enrichment by dbcve.org (CC-BY-4.0). Fetched via API.
Back to CVE