cbcvebase.
CVE-2025-23150
published 2025-05-01

CVE-2025-23150: In the Linux kernel, the following vulnerability has been resolved: ext4: fix off-by-one error in do_split Syzkaller detected a use-after-free issue in…

PriorityP421medium5.5CVSS 3.1
AVLACLPRLUINSUCNINAH
EPSS
0.21%
10.6th percentile
In the Linux kernel, the following vulnerability has been resolved: ext4: fix off-by-one error in do_split Syzkaller detected a use-after-free issue in ext4_insert_dentry that was caused by out-of-bounds access due to incorrect splitting in do_split. BUG: KASAN: use-after-free in ext4_insert_dentry+0x36a/0x6d0 fs/ext4/namei.c:2109 Write of size 251 at addr ffff888074572f14 by task syz-executor335/5847 CPU: 0 UID: 0 PID: 5847 Comm: syz-executor335 Not tainted 6.12.0-rc6-syzkaller-00318-ga9cda7c0ffed #0 Hardware name: Google Google Compute Engine/Google Compute Engine, BIOS Google 10/30/2024 Call Trace: __dump_stack lib/dump_stack.c:94 [inline] dump_stack_lvl+0x241/0x360 lib/dump_stack.c:120 print_address_description mm/kasan/report.c:377 [inline] print_report+0x169/0x550 mm/kasan/report.c:488 kasan_report+0x143/0x180 mm/kasan/report.c:601 kasan_check_range+0x282/0x290 mm/kasan/generic.c:189 __asan_memcpy+0x40/0x70 mm/kasan/shadow.c:106 ext4_insert_dentry+0x36a/0x6d0 fs/ext4/namei.c:2109 add_dirent_to_buf+0x3d9/0x750 fs/ext4/namei.c:2154 make_indexed_dir+0xf98/0x1600 fs/ext4/namei.c:2351 ext4_add_entry+0x222a/0x25d0 fs/ext4/namei.c:2455 ext4_add_nondir+0x8d/0x290 fs/ext4/namei.c:2796 ext4_symlink+0x920/0xb50 fs/ext4/namei.c:3431 vfs_symlink+0x137/0x2e0 fs/namei.c:4615 do_symlinkat+0x222/0x3a0 fs/namei.c:4641 __do_sys_symlink fs/namei.c:4662 [inline] __se_sys_symlink fs/namei.c:4660 [inline] __x64_sys_symlink+0x7a/0x90 fs/namei.c:4660 do_syscall_x64 arch/x86/entry/common.c:52 [inline] do_syscall_64+0xf3/0x230 arch/x86/entry/common.c:83 entry_SYSCALL_64_after_hwframe+0x77/0x7f The following loop is located right above 'if' statement. for (i = count-1; i >= 0; i--) { /* is more than half of this entry in 2nd half of the block? */ if (size + map[i].size/2 > blocksize/2) break; size += map[i].size; move++; } 'i' in this case could go down to -1, in which case sum of active entries wouldn't exceed half the block size, but previous behaviour would also do split in h

Affected

67 ranges· showing 25
VendorProductVersion rangeFixed in
debiandebian_linux
debianlinux< linux 6.1.135-1 (bookworm)linux 6.1.135-1 (bookworm)
debianlinux-6.1< linux 6.1.135-1 (bookworm)linux 6.1.135-1 (bookworm)
linuxlinux
linuxlinux
linuxlinux
linuxlinux
linuxlinux
linuxlinux
linuxlinux
linuxlinux>= 4.14.195 < 4.154.15
linuxlinux>= 4.19.142 < 4.204.20
linuxlinux>= 4.4.234 < 4.54.5
linuxlinux>= 4.9.234 < 4.104.10
linuxlinux>= 5.4.61 < 5.4.2935.4.293
linuxlinux>= 5.7.18 < 5.85.8
linuxlinux>= 5.8.4 < 5.95.9
linuxlinux>= 5872331b3d91820e14716632ebb56b1399b34fe1 < 515c34cff899eb5dae6aa7eee01c1295b07d81af515c34cff899eb5dae6aa7eee01c1295b07d81af
linuxlinux>= 5872331b3d91820e14716632ebb56b1399b34fe1 < 2883e9e74f73f9265e5f8d1aaaa89034b308e4332883e9e74f73f9265e5f8d1aaaa89034b308e433
linuxlinux>= 5872331b3d91820e14716632ebb56b1399b34fe1 < 35d0aa6db9d93307085871ceab8a729594a9816235d0aa6db9d93307085871ceab8a729594a98162
linuxlinux>= 5872331b3d91820e14716632ebb56b1399b34fe1 < 2eeb1085bf7bd5c7ba796ca4119925fa5d336a3f2eeb1085bf7bd5c7ba796ca4119925fa5d336a3f
linuxlinux>= 5872331b3d91820e14716632ebb56b1399b34fe1 < 16d9067f00e3a7d1df7c3aa9c20d214923d27e1016d9067f00e3a7d1df7c3aa9c20d214923d27e10
linuxlinux>= 5872331b3d91820e14716632ebb56b1399b34fe1 < 17df39f455f1289319d4d09e4826aa46852ffd1717df39f455f1289319d4d09e4826aa46852ffd17
linuxlinux>= 5872331b3d91820e14716632ebb56b1399b34fe1 < ab0cc5c25552ae0d20eae94b40a93be11b080fc5ab0cc5c25552ae0d20eae94b40a93be11b080fc5
linuxlinux>= 5872331b3d91820e14716632ebb56b1399b34fe1 < 94824ac9a8aaf2fb3c54b4bdde842db80ffa555d94824ac9a8aaf2fb3c54b4bdde842db80ffa555d

CVSS provenance

nvdv3.15.5MEDIUMCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
osv8.8HIGH
vendor_ubuntu8.8HIGH
vendor_debian5.5MEDIUM
vendor_msrc5.5MEDIUM
vendor_redhat5.5MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.