cbcvebase.
CVE-2025-21736
published 2025-02-27

CVE-2025-21736: In the Linux kernel, the following vulnerability has been resolved: nilfs2: fix possible int overflows in nilfs_fiemap() Since nilfs_bmap_lookup_contig() in…

PriorityP419medium5.5CVSS 3.1
AVLACLPRLUINSUCNINAH
EPSS
0.23%
13.5th percentile
In the Linux kernel, the following vulnerability has been resolved: nilfs2: fix possible int overflows in nilfs_fiemap() Since nilfs_bmap_lookup_contig() in nilfs_fiemap() calculates its result by being prepared to go through potentially maxblocks == INT_MAX blocks, the value in n may experience an overflow caused by left shift of blkbits. While it is extremely unlikely to occur, play it safe and cast right hand expression to wider type to mitigate the issue. Found by Linux Verification Center (linuxtesting.org) with static analysis tool SVACE.

Affected

26 ranges· showing 25
VendorProductVersion rangeFixed in
debianlinux< linux 6.1.129-1 (bookworm)linux 6.1.129-1 (bookworm)
debianlinux-6.1< linux 6.1.129-1 (bookworm)linux 6.1.129-1 (bookworm)
linuxlinux
linuxlinux>= 622daaff0a8975fb5c5b95f24f3234550ba32e92 < 7649937987fed51ed09985da4019d50189fc534e7649937987fed51ed09985da4019d50189fc534e
linuxlinux>= 622daaff0a8975fb5c5b95f24f3234550ba32e92 < 58b1c6881081f5ddfb9a14dc241a74732c0f855c58b1c6881081f5ddfb9a14dc241a74732c0f855c
linuxlinux>= 622daaff0a8975fb5c5b95f24f3234550ba32e92 < 8f41df5fd4c11d26e929a85f7239799641f92da78f41df5fd4c11d26e929a85f7239799641f92da7
linuxlinux>= 622daaff0a8975fb5c5b95f24f3234550ba32e92 < f3d80f34f58445355fa27b9579a449fb186aa64ef3d80f34f58445355fa27b9579a449fb186aa64e
linuxlinux>= 622daaff0a8975fb5c5b95f24f3234550ba32e92 < f2bd0f1ab47822fe5bd699c8458b896c4b2edea1f2bd0f1ab47822fe5bd699c8458b896c4b2edea1
linuxlinux>= 622daaff0a8975fb5c5b95f24f3234550ba32e92 < b9495a9109abc31d3170f7aad7d48aa64610a1a2b9495a9109abc31d3170f7aad7d48aa64610a1a2
linuxlinux>= 622daaff0a8975fb5c5b95f24f3234550ba32e92 < 250423300b4b0335918be187ef3cade248c06e6a250423300b4b0335918be187ef3cade248c06e6a
linuxlinux>= 622daaff0a8975fb5c5b95f24f3234550ba32e92 < 6438ef381c183444f7f9d1de18f22661cba1e9466438ef381c183444f7f9d1de18f22661cba1e946
linuxlinux_kernel>= 0 < 5.10.237-15.10.237-1
linuxlinux_kernel>= 0 < 6.1.129-16.1.129-1
linuxlinux_kernel>= 0 < 6.12.15-16.12.15-1
linuxlinux_kernel>= 0 < 6.12.15-16.12.15-1
linuxlinux_kernel>= 0 < 5.4.0-216.2365.4.0-216.236
linuxlinux_kernel>= 0 < 5.15.0-140.1505.15.0-140.150
linuxlinux_kernel>= 0 < 6.8.0-64.676.8.0-64.67
linuxlinux_kernel>= 2.6.38 < 6.1.1296.1.129
linuxlinux_kernel>= 6.13 < 6.13.36.13.3
linuxlinux_kernel>= 6.2 < 6.6.786.6.78
linuxlinux_kernel>= 6.7 < 6.12.146.12.14
msrcazl3_kernel_6.6.64.2-9_on_azure_linux_3.0
msrcazl3_kernel_6.6.78.1-3_on_azure_linux_3.0
msrccbl2_kernel_5.15.179.1-1_on_cbl_mariner_2.0

CVSS provenance

nvdv3.15.5MEDIUMCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
osv8.8HIGH
vendor_ubuntu8.8HIGH
vendor_debian5.5MEDIUM
vendor_msrc5.5MEDIUM
vendor_redhat5.5MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.