CVE-2025-40167 (GCVE-0-2025-40167)
Vulnerability from cvelistv5
Published
2025-11-12 10:26
Modified
2026-08-05 12:08
Summary
In the Linux kernel, the following vulnerability has been resolved: ext4: detect invalid INLINE_DATA + EXTENTS flag combination syzbot reported a BUG_ON in ext4_es_cache_extent() when opening a verity file on a corrupted ext4 filesystem mounted without a journal. The issue is that the filesystem has an inode with both the INLINE_DATA and EXTENTS flags set: EXT4-fs error (device loop0): ext4_cache_extents:545: inode #15: comm syz.0.17: corrupted extent tree: lblk 0 < prev 66 Investigation revealed that the inode has both flags set: DEBUG: inode 15 - flag=1, i_inline_off=164, has_inline=1, extents_flag=1 This is an invalid combination since an inode should have either: - INLINE_DATA: data stored directly in the inode - EXTENTS: data stored in extent-mapped blocks Having both flags causes ext4_has_inline_data() to return true, skipping extent tree validation in __ext4_iget(). The unvalidated out-of-order extents then trigger a BUG_ON in ext4_es_cache_extent() due to integer underflow when calculating hole sizes. Fix this by detecting this invalid flag combination early in ext4_iget() and rejecting the corrupted inode.
Impacted products
Vendor Product Version
Linux Linux Version: f19d5870cbf72d4cb2a8e1f749dff97af99b071e
Version: f19d5870cbf72d4cb2a8e1f749dff97af99b071e
Version: f19d5870cbf72d4cb2a8e1f749dff97af99b071e
Version: f19d5870cbf72d4cb2a8e1f749dff97af99b071e
Version: f19d5870cbf72d4cb2a8e1f749dff97af99b071e
Version: f19d5870cbf72d4cb2a8e1f749dff97af99b071e
Version: f19d5870cbf72d4cb2a8e1f749dff97af99b071e
Version: f19d5870cbf72d4cb2a8e1f749dff97af99b071e
Create a notification for this product.
Show details on NVD website


{
  "containers": {
    "cna": {
      "affected": [
        {
          "defaultStatus": "unaffected",
          "product": "Linux",
          "programFiles": [
            "fs/ext4/inode.c"
          ],
          "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
          "vendor": "Linux",
          "versions": [
            {
              "lessThan": "4954d297c91d292630ab43ba4d195dc371ce65d3",
              "status": "affected",
              "version": "f19d5870cbf72d4cb2a8e1f749dff97af99b071e",
              "versionType": "git"
            },
            {
              "lessThan": "f061f7c331fc16250fc82aa68964f35821687217",
              "status": "affected",
              "version": "f19d5870cbf72d4cb2a8e1f749dff97af99b071e",
              "versionType": "git"
            },
            {
              "lessThan": "2e9e10657b04152ed0d6ecae8d0c02a3405e28f5",
              "status": "affected",
              "version": "f19d5870cbf72d4cb2a8e1f749dff97af99b071e",
              "versionType": "git"
            },
            {
              "lessThan": "1437c95ab2a28b138d4521653583729f61ccb48b",
              "status": "affected",
              "version": "f19d5870cbf72d4cb2a8e1f749dff97af99b071e",
              "versionType": "git"
            },
            {
              "lessThan": "cb6039b68efa547b676a8a10fc4618d9d1865c23",
              "status": "affected",
              "version": "f19d5870cbf72d4cb2a8e1f749dff97af99b071e",
              "versionType": "git"
            },
            {
              "lessThan": "de985264eef64be8a90595908f2e6a87946dad34",
              "status": "affected",
              "version": "f19d5870cbf72d4cb2a8e1f749dff97af99b071e",
              "versionType": "git"
            },
            {
              "lessThan": "1f5ccd22ff482639133f2a0fe08f6d19d0e68717",
              "status": "affected",
              "version": "f19d5870cbf72d4cb2a8e1f749dff97af99b071e",
              "versionType": "git"
            },
            {
              "lessThan": "1d3ad183943b38eec2acf72a0ae98e635dc8456b",
              "status": "affected",
              "version": "f19d5870cbf72d4cb2a8e1f749dff97af99b071e",
              "versionType": "git"
            }
          ]
        },
        {
          "defaultStatus": "affected",
          "product": "Linux",
          "programFiles": [
            "fs/ext4/inode.c"
          ],
          "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
          "vendor": "Linux",
          "versions": [
            {
              "status": "affected",
              "version": "3.8"
            },
            {
              "lessThan": "3.8",
              "status": "unaffected",
              "version": "0",
              "versionType": "semver"
            },
            {
              "lessThanOrEqual": "5.4.*",
              "status": "unaffected",
              "version": "5.4.301",
              "versionType": "semver"
            },
            {
              "lessThanOrEqual": "5.10.*",
              "status": "unaffected",
              "version": "5.10.246",
              "versionType": "semver"
            },
            {
              "lessThanOrEqual": "5.15.*",
              "status": "unaffected",
              "version": "5.15.196",
              "versionType": "semver"
            },
            {
              "lessThanOrEqual": "6.1.*",
              "status": "unaffected",
              "version": "6.1.158",
              "versionType": "semver"
            },
            {
              "lessThanOrEqual": "6.6.*",
              "status": "unaffected",
              "version": "6.6.114",
              "versionType": "semver"
            },
            {
              "lessThanOrEqual": "6.12.*",
              "status": "unaffected",
              "version": "6.12.55",
              "versionType": "semver"
            },
            {
              "lessThanOrEqual": "6.17.*",
              "status": "unaffected",
              "version": "6.17.5",
              "versionType": "semver"
            },
            {
              "lessThanOrEqual": "*",
              "status": "unaffected",
              "version": "6.18",
              "versionType": "original_commit_for_fix"
            }
          ]
        }
      ],
      "cpeApplicability": [
        {
          "nodes": [
            {
              "cpeMatch": [
                {
                  "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                  "versionEndExcluding": "5.4.301",
                  "versionStartIncluding": "3.8",
                  "vulnerable": true
                },
                {
                  "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                  "versionEndExcluding": "5.10.246",
                  "versionStartIncluding": "3.8",
                  "vulnerable": true
                },
                {
                  "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                  "versionEndExcluding": "5.15.196",
                  "versionStartIncluding": "3.8",
                  "vulnerable": true
                },
                {
                  "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                  "versionEndExcluding": "6.1.158",
                  "versionStartIncluding": "3.8",
                  "vulnerable": true
                },
                {
                  "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                  "versionEndExcluding": "6.6.114",
                  "versionStartIncluding": "3.8",
                  "vulnerable": true
                },
                {
                  "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                  "versionEndExcluding": "6.12.55",
                  "versionStartIncluding": "3.8",
                  "vulnerable": true
                },
                {
                  "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                  "versionEndExcluding": "6.17.5",
                  "versionStartIncluding": "3.8",
                  "vulnerable": true
                },
                {
                  "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                  "versionEndExcluding": "6.18",
                  "versionStartIncluding": "3.8",
                  "vulnerable": true
                }
              ],
              "negate": false,
              "operator": "OR"
            }
          ]
        }
      ],
      "descriptions": [
        {
          "lang": "en",
          "value": "In the Linux kernel, the following vulnerability has been resolved:\n\next4: detect invalid INLINE_DATA + EXTENTS flag combination\n\nsyzbot reported a BUG_ON in ext4_es_cache_extent() when opening a verity\nfile on a corrupted ext4 filesystem mounted without a journal.\n\nThe issue is that the filesystem has an inode with both the INLINE_DATA\nand EXTENTS flags set:\n\n    EXT4-fs error (device loop0): ext4_cache_extents:545: inode #15:\n    comm syz.0.17: corrupted extent tree: lblk 0 \u003c prev 66\n\nInvestigation revealed that the inode has both flags set:\n    DEBUG: inode 15 - flag=1, i_inline_off=164, has_inline=1, extents_flag=1\n\nThis is an invalid combination since an inode should have either:\n- INLINE_DATA: data stored directly in the inode\n- EXTENTS: data stored in extent-mapped blocks\n\nHaving both flags causes ext4_has_inline_data() to return true, skipping\nextent tree validation in __ext4_iget(). The unvalidated out-of-order\nextents then trigger a BUG_ON in ext4_es_cache_extent() due to integer\nunderflow when calculating hole sizes.\n\nFix this by detecting this invalid flag combination early in ext4_iget()\nand rejecting the corrupted inode."
        }
      ],
      "metrics": [
        {
          "cvssV3_1": {
            "baseScore": 7.8,
            "baseSeverity": "HIGH",
            "vectorString": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H",
            "version": "3.1"
          },
          "scenarios": [
            {
              "lang": "en",
              "value": "AV:L - The invalid flag combination can only be delivered on a crafted ext4 on-disk image attached locally (USB stick, SD card, loop-mounted file), and the bug fires during `ext4_iget()`/`ext4_map_blocks()` on the local mount; there is no network-facing input into this code path.\nAC:L - The attacker fully controls the image and merely sets both INLINE_DATA_FL and EXTENTS_FL on an inode with a `system.data` xattr, formatting without a journal \u2014 this deterministically bypasses `ext4_ext_check_inode()` and trips `BUG_ON(end \u003c lblk)` on every open, with no race, timing, or memory-layout condition outside the attacker\u0027s control.\nPR:N - The attacker needs no account or privilege on the target \u2014 they only supply the malicious filesystem image, and the privileged mount plus the subsequent file access are performed by the victim, an indexer/thumbnailer, or an automounter such as udisks2 or vold.\nUI:R - Because `ext4_fs_type` lacks `FS_USERNS_MOUNT` and `INLINE_DATA_FL` is not in `EXT4_FL_USER_MODIFIABLE`, the corrupt inode cannot be created on a live filesystem; a user or automounter must actually mount the attacker-supplied ext4 image.\nS:U - The out-of-bounds accesses and the panic are confined to the mounting host\u0027s kernel memory and its own filesystem, within a single security authority; no VM, hypervisor, IOMMU, or sandbox boundary is crossed.\nC:H - Skipping `__ext4_ext_check()` leaves `eh_entries` unvalidated (up to 65535 versus the 4 that fit in the 60-byte `i_block[]`), so `ext4_cache_extents()` and `ext4_ext_binsearch()` read hundreds of kilobytes past the `ext4_inode_info` slab object, and those out-of-bounds kernel bytes are interpreted as physical block numbers that drive real disk reads and are reported back to userspace through FIEMAP.\nI:H - The unvalidated `eh_max` defeats the `eh_entries \u003e= eh_max` guard in `ext4_ext_insert_extent()`, so extent entries are memmoved and written past the end of `i_block[]` into adjacent `ext4_inode_info` slab fields, giving a heap out-of-bounds write; the missing `ext4_valid_extent()`/`ext4_inode_block_valid()` check additionally lets writes and block frees land on superblock, bitmap, and group-descriptor blocks.\nA:H - The out-of-order extents produce an integer underflow in `lblk - prev` and hit `BUG_ON(end \u003c lblk)` in `ext4_es_cache_extent()`, an immediate and reliably reproducible kernel panic on every access to the crafted file; the out-of-bounds slab reads independently oops the kernel on KASAN and hardened builds."
            }
          ]
        }
      ],
      "providerMetadata": {
        "dateUpdated": "2026-08-05T12:08:12.384Z",
        "orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
        "shortName": "Linux"
      },
      "references": [
        {
          "url": "https://git.kernel.org/stable/c/4954d297c91d292630ab43ba4d195dc371ce65d3"
        },
        {
          "url": "https://git.kernel.org/stable/c/f061f7c331fc16250fc82aa68964f35821687217"
        },
        {
          "url": "https://git.kernel.org/stable/c/2e9e10657b04152ed0d6ecae8d0c02a3405e28f5"
        },
        {
          "url": "https://git.kernel.org/stable/c/1437c95ab2a28b138d4521653583729f61ccb48b"
        },
        {
          "url": "https://git.kernel.org/stable/c/cb6039b68efa547b676a8a10fc4618d9d1865c23"
        },
        {
          "url": "https://git.kernel.org/stable/c/de985264eef64be8a90595908f2e6a87946dad34"
        },
        {
          "url": "https://git.kernel.org/stable/c/1f5ccd22ff482639133f2a0fe08f6d19d0e68717"
        },
        {
          "url": "https://git.kernel.org/stable/c/1d3ad183943b38eec2acf72a0ae98e635dc8456b"
        }
      ],
      "title": "ext4: detect invalid INLINE_DATA + EXTENTS flag combination",
      "x_generator": {
        "engine": "bippy-1.2.0"
      }
    }
  },
  "cveMetadata": {
    "assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
    "assignerShortName": "Linux",
    "cveId": "CVE-2025-40167",
    "datePublished": "2025-11-12T10:26:24.498Z",
    "dateReserved": "2025-04-16T07:20:57.176Z",
    "dateUpdated": "2026-08-05T12:08:12.384Z",
    "state": "PUBLISHED"
  },
  "dataType": "CVE_RECORD",
  "dataVersion": "5.2"
}


Log in or create an account to share your comment.




Tags
Taxonomy of the tags.


Loading…

Loading…

Loading…

Sightings

Author Source Type Date

Nomenclature

  • Seen: The vulnerability was mentioned, discussed, or seen somewhere by the user.
  • Confirmed: The vulnerability is confirmed from an analyst perspective.
  • Published Proof of Concept: A public proof of concept is available for this vulnerability.
  • Exploited: This vulnerability was exploited and seen by the user reporting the sighting.
  • Patched: This vulnerability was successfully patched by the user reporting the sighting.
  • Not exploited: This vulnerability was not exploited or seen by the user reporting the sighting.
  • Not confirmed: The user expresses doubt about the veracity of the vulnerability.
  • Not patched: This vulnerability was not successfully patched by the user reporting the sighting.


Loading…

Loading…