CVE-2025-22114 (GCVE-0-2025-22114)
Vulnerability from cvelistv5
Published
2025-04-16 14:12
Modified
2026-08-05 11:56
Summary
In the Linux kernel, the following vulnerability has been resolved: btrfs: don't clobber ret in btrfs_validate_super() Commit 2a9bb78cfd36 ("btrfs: validate system chunk array at btrfs_validate_super()") introduces a call to validate_sys_chunk_array() in btrfs_validate_super(), which clobbers the value of ret set earlier. This has the effect of negating the validity checks done earlier, making it so btrfs could potentially try to mount invalid filesystems.
Impacted products
Vendor Product Version
Linux Linux Version: 2a9bb78cfd367fdeff74f15b1e98969912292d9e
Version: 2a9bb78cfd367fdeff74f15b1e98969912292d9e
Create a notification for this product.
Show details on NVD website


{
  "containers": {
    "cna": {
      "affected": [
        {
          "defaultStatus": "unaffected",
          "product": "Linux",
          "programFiles": [
            "fs/btrfs/disk-io.c"
          ],
          "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
          "vendor": "Linux",
          "versions": [
            {
              "lessThan": "ef6800a2015e706e9852a5ec15263fec9990d012",
              "status": "affected",
              "version": "2a9bb78cfd367fdeff74f15b1e98969912292d9e",
              "versionType": "git"
            },
            {
              "lessThan": "9db9c7dd5b4e1d3205137a094805980082c37716",
              "status": "affected",
              "version": "2a9bb78cfd367fdeff74f15b1e98969912292d9e",
              "versionType": "git"
            }
          ]
        },
        {
          "defaultStatus": "affected",
          "product": "Linux",
          "programFiles": [
            "fs/btrfs/disk-io.c"
          ],
          "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
          "vendor": "Linux",
          "versions": [
            {
              "status": "affected",
              "version": "6.14"
            },
            {
              "lessThan": "6.14",
              "status": "unaffected",
              "version": "0",
              "versionType": "semver"
            },
            {
              "lessThanOrEqual": "6.14.*",
              "status": "unaffected",
              "version": "6.14.2",
              "versionType": "semver"
            },
            {
              "lessThanOrEqual": "*",
              "status": "unaffected",
              "version": "6.15",
              "versionType": "original_commit_for_fix"
            }
          ]
        }
      ],
      "cpeApplicability": [
        {
          "nodes": [
            {
              "cpeMatch": [
                {
                  "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                  "versionEndExcluding": "6.14.2",
                  "versionStartIncluding": "6.14",
                  "vulnerable": true
                },
                {
                  "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                  "versionEndExcluding": "6.15",
                  "versionStartIncluding": "6.14",
                  "vulnerable": true
                }
              ],
              "negate": false,
              "operator": "OR"
            }
          ]
        }
      ],
      "descriptions": [
        {
          "lang": "en",
          "value": "In the Linux kernel, the following vulnerability has been resolved:\n\nbtrfs: don\u0027t clobber ret in btrfs_validate_super()\n\nCommit 2a9bb78cfd36 (\"btrfs: validate system chunk array at\nbtrfs_validate_super()\") introduces a call to validate_sys_chunk_array()\nin btrfs_validate_super(), which clobbers the value of ret set earlier.\nThis has the effect of negating the validity checks done earlier, making\nit so btrfs could potentially try to mount invalid filesystems."
        }
      ],
      "metrics": [
        {
          "cvssV3_1": {
            "baseScore": 7.8,
            "baseSeverity": "HIGH",
            "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
            "version": "3.1"
          },
          "scenarios": [
            {
              "lang": "en",
              "value": "AV:L - The vulnerability is reached by mounting a crafted btrfs image via the mount(2) path (open_ctree \u2192 btrfs_validate_mount_super), requiring local system access. Desktop distros brokering loop-device setup and mounting to active local sessions through udisks2/polkit make this a genuine local (not merely physical) path, alongside removable-media automount on kiosks and shared workstations.\nAC:L - The entire image is crafted deterministically offline \u2014 a valid superblock checksum, a legitimate 65+ byte sys_chunk_array so validate_sys_chunk_array() returns 0 and clobbers ret, sectorsize=4096 to satisfy alignment checks, and nodesize=1 MiB to overflow the 16-entry page/folio arrays. There is no race, no memory-layout dependency, and no condition outside the attacker\u0027s control.\nPR:L - On default desktop configurations an unprivileged local user in an active session can create a loop device and mount an arbitrary filesystem image through udisks2/polkit without additional authentication, and containers or fstab \"user\" entries provide equivalent paths. No real root in the init namespace is needed.\nUI:N - In the loop-device scenario the attacker performs the mount themselves; no separate victim has to open a file, click a prompt, or take any action.\nS:U - The corruption occurs in kernel memory during filesystem mount and is confined to the kernel\u0027s own security authority \u2014 there is no VM, IOMMU, or sandbox boundary crossed.\nC:H - The bypassed nodesize check yields an extent_buffer whose len vastly exceeds its backing storage, giving out-of-bounds reads of kernel memory, and BTRFS_MAX_ITEM_SIZE/csums_per_leaf underflow to enormous values; the bypassed fsid/metadata_uuid/dev_item.fsid checks additionally let a crafted device impersonate another filesystem. The resulting heap and stack corruption is leverageable for arbitrary kernel memory disclosure.\nI:H - btrfs_alloc_page_array() writes an attacker-chosen number of struct page pointers past a 16-entry on-stack array and past the extent_buffer slab object, an out-of-bounds write primitive exploitable for control-flow hijack. The same clobber also defeats btrfs_validate_write_super(), permitting corrupt superblocks to be committed to disk.\nA:H - The overflow reliably panics the kernel \u2014 via BUG() from the ASSERT where CONFIG_BTRFS_ASSERT is set, via stack-protector panic, or via oops from the nonsensical geometry (invalid sectorsize_bits shifts, zero/oversized nodesize) propagated throughout the mounted filesystem."
            }
          ]
        }
      ],
      "providerMetadata": {
        "dateUpdated": "2026-08-05T11:56:51.717Z",
        "orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
        "shortName": "Linux"
      },
      "references": [
        {
          "url": "https://git.kernel.org/stable/c/ef6800a2015e706e9852a5ec15263fec9990d012"
        },
        {
          "url": "https://git.kernel.org/stable/c/9db9c7dd5b4e1d3205137a094805980082c37716"
        }
      ],
      "title": "btrfs: don\u0027t clobber ret in btrfs_validate_super()",
      "x_generator": {
        "engine": "bippy-1.2.0"
      }
    }
  },
  "cveMetadata": {
    "assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
    "assignerShortName": "Linux",
    "cveId": "CVE-2025-22114",
    "datePublished": "2025-04-16T14:12:59.898Z",
    "dateReserved": "2024-12-29T08:45:45.823Z",
    "dateUpdated": "2026-08-05T11:56:51.717Z",
    "state": "PUBLISHED"
  },
  "dataType": "CVE_RECORD",
  "dataVersion": "5.2"
}


Log in or create an account to share your comment.




Tags
Taxonomy of the tags.


Loading…

Loading…

Loading…

Sightings

Author Source Type Date

Nomenclature

  • Seen: The vulnerability was mentioned, discussed, or seen somewhere by the user.
  • Confirmed: The vulnerability is confirmed from an analyst perspective.
  • Published Proof of Concept: A public proof of concept is available for this vulnerability.
  • Exploited: This vulnerability was exploited and seen by the user reporting the sighting.
  • Patched: This vulnerability was successfully patched by the user reporting the sighting.
  • Not exploited: This vulnerability was not exploited or seen by the user reporting the sighting.
  • Not confirmed: The user expresses doubt about the veracity of the vulnerability.
  • Not patched: This vulnerability was not successfully patched by the user reporting the sighting.


Loading…

Loading…