cbcvebase.
CVE-2025-21721
published 2025-02-27

CVE-2025-21721: In the Linux kernel, the following vulnerability has been resolved: nilfs2: handle errors that nilfs_prepare_chunk() may return Patch series "nilfs2: fix…

PriorityP420medium5.5CVSS 3.1
AVLACLPRLUINSUCNINAH
EPSS
0.20%
10.1th percentile
In the Linux kernel, the following vulnerability has been resolved: nilfs2: handle errors that nilfs_prepare_chunk() may return Patch series "nilfs2: fix issues with rename operations". This series fixes BUG_ON check failures reported by syzbot around rename operations, and a minor behavioral issue where the mtime of a child directory changes when it is renamed instead of moved. This patch (of 2): The directory manipulation routines nilfs_set_link() and nilfs_delete_entry() rewrite the directory entry in the folio/page previously read by nilfs_find_entry(), so error handling is omitted on the assumption that nilfs_prepare_chunk(), which prepares the buffer for rewriting, will always succeed for these. And if an error is returned, it triggers the legacy BUG_ON() checks in each routine. This assumption is wrong, as proven by syzbot: the buffer layer called by nilfs_prepare_chunk() may call nilfs_get_block() if necessary, which may fail due to metadata corruption or other reasons. This has been there all along, but improved sanity checks and error handling may have made it more reproducible in fuzzing tests. Fix this issue by adding missing error paths in nilfs_set_link(), nilfs_delete_entry(), and their caller nilfs_rename().

Affected

25 ranges
VendorProductVersion rangeFixed in
debianlinux< linux 6.1.133-1 (bookworm)linux 6.1.133-1 (bookworm)
debianlinux-6.1< linux 6.1.133-1 (bookworm)linux 6.1.133-1 (bookworm)
linuxlinux
linuxlinux>= 2ba466d74ed74f073257f86e61519cb8f8f46184 < b38c6c260c2415c7f0968871305e7a093daabb4cb38c6c260c2415c7f0968871305e7a093daabb4c
linuxlinux>= 2ba466d74ed74f073257f86e61519cb8f8f46184 < f70bd2d8ca454e0ed78970f72147ca321dbaa015f70bd2d8ca454e0ed78970f72147ca321dbaa015
linuxlinux>= 2ba466d74ed74f073257f86e61519cb8f8f46184 < 607dc724b162f4452dc768865e578c1a509a1c8c607dc724b162f4452dc768865e578c1a509a1c8c
linuxlinux>= 2ba466d74ed74f073257f86e61519cb8f8f46184 < 1ee2d454baa361d2964e3e2f2cca9ee3f769d93c1ee2d454baa361d2964e3e2f2cca9ee3f769d93c
linuxlinux>= 2ba466d74ed74f073257f86e61519cb8f8f46184 < 7891ac3b0a5c56f7148af507306308ab841cdc317891ac3b0a5c56f7148af507306308ab841cdc31
linuxlinux>= 2ba466d74ed74f073257f86e61519cb8f8f46184 < eddd3176b8c4c83a46ab974574cda7c3dfe09388eddd3176b8c4c83a46ab974574cda7c3dfe09388
linuxlinux>= 2ba466d74ed74f073257f86e61519cb8f8f46184 < 481136234dfe96c7f92770829bec6111c7c5f5dd481136234dfe96c7f92770829bec6111c7c5f5dd
linuxlinux>= 2ba466d74ed74f073257f86e61519cb8f8f46184 < ee70999a988b8abc3490609142f50ebaa8344432ee70999a988b8abc3490609142f50ebaa8344432
linuxlinux_kernel>= 0 < 5.10.237-15.10.237-1
linuxlinux_kernel>= 0 < 6.1.133-16.1.133-1
linuxlinux_kernel>= 0 < 6.12.13-16.12.13-1
linuxlinux_kernel>= 0 < 6.12.13-16.12.13-1
linuxlinux_kernel>= 0 < 5.4.0-216.2365.4.0-216.236
linuxlinux_kernel>= 0 < 5.15.0-140.1505.15.0-140.150
linuxlinux_kernel>= 0 < 6.8.0-64.676.8.0-64.67
linuxlinux_kernel>= 2.6.30 < 5.4.2915.4.291
linuxlinux_kernel>= 5.11 < 5.15.1795.15.179
linuxlinux_kernel>= 5.16 < 6.1.1316.1.131
linuxlinux_kernel>= 5.5 < 5.10.2355.10.235
linuxlinux_kernel>= 6.13 < 6.13.26.13.2
linuxlinux_kernel>= 6.2 < 6.6.806.6.80
linuxlinux_kernel>= 6.7 < 6.12.136.12.13

CVSS provenance

nvdv3.15.5MEDIUMCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
osv8.8HIGH
vendor_ubuntu8.8HIGH
vendor_debian5.5MEDIUM
vendor_redhat5.5MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.