Linux 7.3-rc3 disables EROFS LZ4 rolling decompression after AWS personnel identified rare LZ4 inputs that could corrupt data. The upstream LZ4 implementation can perform uncontrolled backward memory copies, violating EROFS's assumption that non-overlapping ranges are copied forward. The temporary mitigation favors correctness but can add substantial decompression memory use—up to 146 pages per request in a cited workload—partially offset by a reserved decompression-buffer pool.
The release candidate also contains SMB client hardening, including fixes for a potential heap overflow in DACL rewriting, oversized-DACL rejection, and malformed read-response validation, along with a Landlock use-after-free fix. EROFS rolling decompression may return if upstream LZ4 provides the required copy-direction guarantees or EROFS adopts a maintained local implementation.

See real exploitation activity before you spend the cycle.
3 events from the most recent confirmed update back to the earliest known activity.
Linus Torvalds issued Linux 7.3-rc3, including SMB client fixes for a potential DACL-rewriting heap overflow, oversized DACL rejection, and malformed read-response validation. The release also fixed a Landlock use-after-free issue and incorporated the EROFS LZ4 rolling-decompression disablement.
EROFS temporarily disabled LZ4 rolling decompression to prioritize correctness while the underlying corruption risk remains unresolved. The change increases temporary memory use during decompression; a reserved LZ4 buffer pool added by commit 0f6273ab4637 partially mitigates that impact.
AWS personnel identified rare LZ4 datasets for which EROFS rolling decompression could return corrupted data. The issue was traced to upstream LZ4 literal-copy behavior that can perform backward memory copies, violating EROFS rolling-window assumptions.
See real exploitation activity behind this advisory so you can triage it against everything else in the queue.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.