PT-2025-18419 · Linux+10 · Linux Kernel+10

Published

2025-03-17

·

Updated

2026-04-20

·

CVE-2025-37738

CVSS v3.1

7.8

High

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Linux kernel versions prior to 6.13.0-rc2+
Description A slab-use-after-free bug has been identified in the Linux kernel, specifically in the ext4 file system. The issue arises when the kernel fails to ignore extended attributes past the 'end' entry within the 'ext4 xattr inode dec ref all' function. This bug can lead to incorrect memory access and potentially cause system instability or crashes. The issue was reported by KASAN (Kernel Address Sanitizer) and has been fixed.
Recommendations To resolve this issue, update the Linux kernel to a version newer than 6.13.0-rc2+. As a temporary workaround, consider disabling the ext4 xattr inode dec ref all function until a patch is available. However, this is not a recommended long-term solution, as it may cause other issues with the file system. The best course of action is to apply the official patch or update to a newer kernel version.

Exploit

Fix

Use After Free

Weakness Enumeration

Related Identifiers

ALSA-2025:11298
ALSA-2025:11299
ALSA-2025:9302
BDU:2025-12089
CESA-2025_11298
CESA-2025_11299
CVE-2025-37738
DLA-4178-1
DLA-4193-1
ECHO-C0B7-1AC1-88DE
INFSA-2025_11298
INFSA-2025_11299
INFSA-2025_9302
OESA-2025-1594
OESA-2025-1595
OESA-2025-1667
OESA-2025-1668
RHSA-2025:10671
RHSA-2025:10675
RHSA-2025:10829
RHSA-2025:10830
RHSA-2025:11245
RHSA-2025:11298
RHSA-2025:11299
RHSA-2025:12238
RHSA-2025:12623
RHSA-2025:13061
RHSA-2025:13099
RHSA-2025:9302
RHSA-2025:9348
RHSA-2025_11298
RHSA-2025_11299
RHSA-2025_9302
SUSE-SU-2025:02249-1
SUSE-SU-2025:02254-1
SUSE-SU-2025:02307-1
SUSE-SU-2025:02333-1
SUSE-SU-2025:02335-1
SUSE-SU-2025:02538-1
SUSE-SU-2025:02923-1
SUSE-SU-2025:03615-1
SUSE-SU-2025:03628-1
SUSE-SU-2025:20413-1
SUSE-SU-2025:20421-1
SUSE-SU-2025:3716-1
SUSE-SU-2025:3761-1
SUSE-SU-2025_02249-1
SUSE-SU-2025_02254-1
SUSE-SU-2025_02307-1
SUSE-SU-2025_02333-1
SUSE-SU-2025_02335-1
SUSE-SU-2025_02538-1
USN-7594-1
USN-7594-2
USN-7594-3
USN-7654-1
USN-7654-2
USN-7654-3
USN-7654-4
USN-7654-5
USN-7655-1
USN-7686-1
USN-7711-1
USN-7712-1
USN-7712-2
USN-8028-1
USN-8028-2
USN-8028-3
USN-8028-4
USN-8028-5
USN-8028-6
USN-8028-7
USN-8028-8
USN-8031-1
USN-8031-2
USN-8031-3
USN-8052-1
USN-8052-2
USN-8074-1
USN-8074-2
USN-8126-1

Affected Products

Almalinux
Astra Linux
Centos
Debian
Linuxmint
Linux Kernel
Red Hat
Red Os
Rocky Linux
Suse
Ubuntu