PT-2025-46594 · Ext4+3 · Ext4+3

Published

2025-01-01

·

Updated

2026-02-24

·

CVE-2025-40119

CVSS v2.0

4.3

Medium

VectorAV:A/AC:H/Au:S/C:N/I:N/A:C
Name of the Vulnerable Software and Affected Versions Linux kernel versions prior to 6.17.0-rc2 #1134
Description The Linux kernel contains a flaw in the ext4 file system related to memory management during initialization. Specifically, a null pointer dereference can occur in the ext4 mb init() function when ext4 mb avg fragment size destroy() is called with an uninitialized sbi->s mb avg fragment size. This happens when groupinfo slab cache allocation fails. The lack of null pointer checking in ext4 mb avg fragment size destroy() leads to the dereference, potentially causing system instability. The same fix was applied to ext4 mb largest free orders destroy().
Recommendations Update to a version newer than 6.17.0-rc2 #1134.

Exploit

Fix

NULL Pointer Dereference

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2025-15344
CVE-2025-40119
USN-8029-1
USN-8029-2
USN-8029-3
USN-8030-1
USN-8048-1

Affected Products

Linuxmint
Linux Kernel
Ubuntu
Ext4