PT-2025-35974 · Ext4+6 · Ext4+6

·

CVE-2025-38701

·

Publicado

2025-07-17

·

Atualizado

2026-07-11

CVSS v3.1

5.5

Média

VetorAV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
Nome do Software Vulnerável e Versões Afetadas Kernel Linux (versões afetadas não especificadas)
Descrição O kernel Linux contém uma falha na qual um sistema de arquivos submetido a fuzzing malicioso pode disparar um BUG ON na função ext4 update inline data() quando um inode possui a flag INLINE DATA FL definida, mas está ausente o atributo estendido system.data. Este problema foi identificado através do fuzzing do syzbot. A vulnerabilidade é corrigida substituindo BUG ON por EXT4 ERROR INODE() em ext4 update inline data(), ext4 create inline data() e ext4 inline data truncate().
Recomendações Atualmente, não há informações sobre uma versão mais recente que contenha uma correção para esta vulnerabilidade.

Exploit

DoS

Assertion Failure

RCE

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

AZL-66899
AZL-73881
BDU:2025-15547
CVE-2025-38701
DLA-4327-1
DLA-4328-1
DSA-6009-1
ECHO-8425-474F-65AB
MGASA-2025-0234
MGASA-2025-0235
OESA-2025-2532
OESA-2025-2536
OESA-2025-2537
OPENSUSE-SU-2025:20081-1
SUSE-SU-2025:03600-1
SUSE-SU-2025:03601-1
SUSE-SU-2025:03602-1
SUSE-SU-2025:03614-1
SUSE-SU-2025:03633-1
SUSE-SU-2025:03634-1
SUSE-SU-2025:20851-1
SUSE-SU-2025:20861-1
SUSE-SU-2025:20870-1
SUSE-SU-2025:20898-1
SUSE-SU-2025:21074-1
SUSE-SU-2025:21139-1
SUSE-SU-2025:21179-1
SUSE-SU-2025:3725-1
SUSE-SU-2025:3751-1
SUSE-SU-2026:20560-1
USN-7909-1
USN-7909-2
USN-7909-3
USN-7909-4
USN-7909-5
USN-7910-1
USN-7910-2
USN-7933-1
USN-7938-1
USN-8028-1
USN-8028-2
USN-8028-3
USN-8028-4
USN-8028-5
USN-8028-6
USN-8028-7
USN-8028-8
USN-8031-1
USN-8031-2
USN-8031-3
USN-8052-1
USN-8052-2
USN-8074-1
USN-8074-2
USN-8126-1

Produtos afetados

Debian
Linuxmint
Linux Kernel
Red Os
Suse
Ubuntu
Ext4