---
cve: "CVE-2026-80697"
severity: "LOW"
cvss: 3.1
epss: "3.9%"
vendor: "Linux"
kev: false
exploited: false
published: "2026-08-28 08:16:55"
tags: [cve, security, low]
source: tsecurity.de CVE-Dossier
exported: "2026-09-03T08:41:02+02:00"
---

# CVE-2026-80697

> 3.1 LOW

## Beschreibung

In the Linux kernel, the following vulnerability has been resolved:

erofs: ensure valid f_path for page cache sharing

Previously, backing files for page cache sharing were set up with
f_path left as NULL (only f_inode was valid).  It worked, but a recent
mincore fix relies on f_path.mnt and crashes (found by "erofs/028" on
7.2-rc4):

 BUG: kernel NULL pointer dereference, address: 0000000000000018
 #PF: supervisor read access in kernel mode
 #PF: error_code(0x0000) - not-present page
 PGD 0 P4D 0
 Oops: Oops: 0000 [#1] SMP PTI
 CPU: 3 UID: 0 PID: 675528 Comm: fincore Not tainted 7.2.0-rc4-00002-g[]-dirty #1 PREEMPT(lazy)
 Hardware name: Red Hat KVM, BIOS 1.16.0-4.al8 04/01/2014
 RIP: 0010:__do_sys_mincore+0xc0/0x2c0
 ...

Specify valid paths using valid disconnected dentries together with
erofs_ishare_mnt instead of leaving f_path empty, so they are more
like real backing files in a pseudo filesystem and standard
backing_file_open() can be used directly.

## Patch verfügbar (OSV)

- Kernel ≥ 7.1.8

## Referenzen

- <https://git.kernel.org/stable/c/3879657c4ffd81b9a42cf575fc6cb60201032587>
- <https://git.kernel.org/stable/c/96b2dbbe58a1ea5df8d29c2fe24b5f04715f4443>

---
_Exportiert aus dem [tsecurity.de CVE-Dossier](https://tsecurity.de/cve?cve=CVE-2026-80697) · Datenquellen: EUVD (ENISA), NVD, OSV, CISA KEV, FIRST EPSS, Exploit-DB, BSI BITS_
