CVE-2026-53174

Description

A flaw was found in the Linux kernel's overlay filesystem (ovl) component. Specifically, an issue in the ovl_iterate_merged() function incorrectly stores an error pointer even after a successful cache operation. This can lead to the function returning a misleading non-zero error, potentially causing unexpected behavior or instability within the system. This vulnerability is related to incorrect error handling during directory iteration.

Understanding the Weakness (CWE)

Availability,Integrity

Technical Impact: Unexpected State; DoS: Crash, Exit, or Restart

An unexpected return value could place the system in a state that could lead to a crash or other unintended behaviors.

Frequently Asked Questions

Want to get errata notifications? Sign up here.