PT-2025-18422 · Linux+6 · Linux Kernel+6

Published

2025-02-20

·

Updated

2026-05-26

·

CVE-2025-37741

CVSS v3.1

5.5

Medium

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions Linux kernel versions prior to 6.12.0-rc7
Description A deadlock vulnerability has been identified in the Linux kernel, specifically in the jfs file system. The issue arises when the ioctl$LOOP SET STATUS64 function is called with an offset value of 4, which does not match the mounted loop device, causing the device's mapping to be invalidated. This can lead to a deadlock when the diFree function is called. The vulnerability is caused by the corruption of metapage data when reading the fixed disk inode (AIT) in raw mode, resulting in a nlink value of 0 being assigned to the iag inode. To avoid this, the nlink value of the dinode should be checked before setting the iag inode.
Recommendations To resolve this issue, update the Linux kernel to a version later than 6.12.0-rc7. As a temporary workaround, consider disabling the diFree function until a patch is available. Additionally, restrict access to the jfs imap.c module to minimize the risk of exploitation. Avoid using the ioctl$LOOP SET STATUS64 function with an offset value of 4 until the issue is resolved.

Exploit

Fix

DoS

Improper Locking

Weakness Enumeration

Related Identifiers

BDU:2025-12343
CVE-2025-37741
DLA-4178-1
DLA-4193-1
ECHO-EC74-7039-416A
OESA-2025-2465
OESA-2025-2466
OESA-2025-2467
SUSE-SU-2025:01964-1
SUSE-SU-2025:01965-1
SUSE-SU-2025:02000-1
SUSE-SU-2025:02254-1
SUSE-SU-2025:02307-1
SUSE-SU-2025:02333-1
SUSE-SU-2025:02923-1
SUSE-SU-2025:20408-1
SUSE-SU-2025:20413-1
SUSE-SU-2025:20419-1
SUSE-SU-2025:20421-1
SUSE-SU-2025_01964-1
SUSE-SU-2025_01965-1
SUSE-SU-2025_02000-1
SUSE-SU-2025_02254-1
SUSE-SU-2025_02307-1
SUSE-SU-2025_02333-1
USN-7594-1
USN-7594-2
USN-7594-3
USN-7654-1
USN-7654-2
USN-7654-3
USN-7654-4
USN-7654-5
USN-7655-1
USN-7686-1
USN-7711-1
USN-7712-1
USN-7712-2
USN-8028-1
USN-8028-2
USN-8028-3
USN-8028-4
USN-8028-5
USN-8028-6
USN-8028-7
USN-8028-8
USN-8031-1
USN-8031-2
USN-8031-3
USN-8052-1
USN-8052-2
USN-8074-1
USN-8074-2
USN-8126-1

Affected Products

Astra Linux
Debian
Linuxmint
Linux Kernel
Red Os
Suse
Ubuntu