PT-2025-4346 · Linux+6 · Linux Kernel+6
Marco Nelissen
·
Published
2025-01-02
·
Updated
2026-02-18
·
CVE-2025-21665
CVSS v3.1
5.5
Medium
| Vector | AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H |
Name of the Vulnerable Software and Affected Versions
Linux kernel versions prior to 5.15.177
Linux kernel versions prior to 6.1.127
Linux kernel versions prior to 6.6.74
Linux kernel versions prior to 6.12.11
Description
The issue is related to the
folio seek hole data() function in the Linux kernel, which inadvertently truncates a 64-bit value to 32 bits on 32-bit kernels. This can lead to a possible infinite loop when writing to an xfs filesystem. The vulnerability may allow an attacker to cause a denial of service.Recommendations
For Linux kernel versions prior to 5.15.177, update to version 5.15.177 or later.
For Linux kernel versions prior to 6.1.127, update to version 6.1.127 or later.
For Linux kernel versions prior to 6.6.74, update to version 6.6.74 or later.
For Linux kernel versions prior to 6.12.11, update to version 6.12.11 or later.
As a temporary workaround, consider restricting access to the
folio seek hole data() function until a patch is available.Exploit
Fix
Infinite Loop
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Alt Linux
Astra Linux
Linuxmint
Linux Kernel
Red Os
Suse
Ubuntu