PT-2025-16761 · Linux+8 · Linux Kernel+8

Published

2025-03-18

·

Updated

2026-05-26

·

CVE-2025-22121

CVSS v3.1

7.1

High

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H
Name of the Vulnerable Software and Affected Versions Linux kernel (affected versions not specified)
Description The issue is related to an out-of-bound read in the ext4 xattr inode dec ref all() function. This occurs due to a use-after-free error, as indicated by the KASAN report. The problem arises because ext4 xattr delete inode() does not check if an xattr is valid when it is stored in an inode. To address this, it is suggested to call xattr check inode() to verify the validity of the xattr in the inode, or to perform this check directly in ext4 iget extra inode().
Recommendations To resolve the issue, ensure that the xattr check inode() function is called to verify the validity of xattrs in inodes. As a temporary workaround, consider restricting the use of the ext4 xattr delete inode() function until a patch is available. Additionally, modifying the ext4 iget extra inode() function to directly verify xattr validity can help prevent the issue. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

DoS

Buffer Overflow

Out of bounds Read

Use After Free

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALSA-2025:11855
ALSA-2025:11861
AZL-62660
AZL-69608
BDU:2026-01527
CVE-2025-22121
ECHO-0610-D76C-1735
INFSA-2025_11861
OESA-2025-1463
OESA-2025-1464
OESA-2025-2764
OESA-2025-2769
OPENSUSE-SU-2025_01614-1
OPENSUSE-SU-2025_01707-1
RHSA-2025:10829
RHSA-2025:10830
RHSA-2025:11245
RHSA-2025:11571
RHSA-2025:11572
RHSA-2025:11855
RHSA-2025:11861
RHSA-2025_11861
SUSE-SU-2025:01614-1
SUSE-SU-2025:01707-1
SUSE-SU-2025:01919-1
SUSE-SU-2025:01951-1
SUSE-SU-2025:01964-1
SUSE-SU-2025:01967-1
SUSE-SU-2025:01982-1
SUSE-SU-2025:20343-1
SUSE-SU-2025:20344-1
SUSE-SU-2025:20354-1
SUSE-SU-2025:20355-1
SUSE-SU-2025_01614-1
SUSE-SU-2025_01707-1
SUSE-SU-2025_01951-1
SUSE-SU-2025_01964-1
SUSE-SU-2025_01967-1
SUSE-SU-2025_01982-1
USN-7594-1
USN-7594-2
USN-7594-3
USN-8095-1
USN-8095-2
USN-8095-3
USN-8095-4
USN-8095-5
USN-8096-1
USN-8096-2
USN-8096-3
USN-8096-4
USN-8096-5
USN-8100-1
USN-8116-1
USN-8125-1
USN-8126-1
USN-8141-1
USN-8163-1
USN-8163-2
USN-8165-1
USN-8243-1
USN-8261-1

Affected Products

Almalinux
Debian
Linuxmint
Linux Kernel
Red Hat
Red Os
Rocky Linux
Suse
Ubuntu