PT-2025-4348 · Linux+6 · Linux Kernel+6

Marco Nelissen

·

Publicado

2025-01-08

·

Atualizado

2026-05-26

·

CVE-2025-21667

CVSS v3.1

5.5

Média

VetorAV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions Linux kernel versions prior to 6.1.127 Linux kernel versions prior to 6.6.74 Linux kernel versions prior to 6.12.11
Description The issue is related to the iomap write delalloc scan() function in the Linux kernel, which can lead to an infinite loop due to numerical truncation when writing to an xfs filesystem on 32-bit kernels. This occurs because folio next index() returns an unsigned long, causing iomap write delalloc scan() to inadvertently use a 32-bit position. The estimated number of potentially affected devices is not specified. There is no information about real-world incidents where this issue was exploited.
Recommendations For Linux kernel versions prior to 6.1.127, update to version 6.1.127 or later to resolve the issue. For Linux kernel versions prior to 6.6.74, update to version 6.6.74 or later to resolve the issue. For Linux kernel versions prior to 6.12.11, update to version 6.12.11 or later to resolve the issue. As a temporary workaround, consider avoiding writing to xfs filesystems on 32-bit kernels until the issue is resolved.

Exploit

Correção

DoS

Infinite Loop

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

ALT-PU-2025-12647
ALT-PU-2025-3467
ALT-PU-2025-3500
AZL-56351
AZL-56357
BDU:2025-01391
CVE-2025-21667
DLA-4076-1
DSA-5860-1
OESA-2025-1158
OESA-2025-1159
OESA-2025-1160
OESA-2025-1162
OPENSUSE-SU-2025_0847-1
OPENSUSE-SU-2025_0856-1
OPENSUSE-SU-2025_0955-1
SUSE-SU-2025:0564-1
SUSE-SU-2025:0847-1
SUSE-SU-2025:0856-1
SUSE-SU-2025:0955-1
SUSE-SU-2025:20190-1
SUSE-SU-2025:20192-1
SUSE-SU-2025:20260-1
SUSE-SU-2025:20270-1
SUSE-SU-2025_0847-1
SUSE-SU-2025_0856-1
SUSE-SU-2025_0955-1
USN-7445-1
USN-7448-1
USN-7595-1
USN-7595-2
USN-7595-3
USN-7595-4
USN-7595-5
USN-7596-1
USN-7596-2
USN-7653-1

Produtos afetados

Alt Linux
Astra Linux
Linuxmint
Linux Kernel
Red Os
Suse
Ubuntu