cbcvebase.
CVE-2025-38701
published 2025-09-04

CVE-2025-38701: In the Linux kernel, the following vulnerability has been resolved: ext4: do not BUG when INLINE_DATA_FL lacks system.data xattr A syzbot fuzzed image…

medium5.5CVSS 3.1
AVLACLPRLUINSUCNINAH
In the Linux kernel, the following vulnerability has been resolved: ext4: do not BUG when INLINE_DATA_FL lacks system.data xattr A syzbot fuzzed image triggered a BUG_ON in ext4_update_inline_data() when an inode had the INLINE_DATA_FL flag set but was missing the system.data extended attribute. Since this can happen due to a maiciouly fuzzed file system, we shouldn't BUG, but rather, report it as a corrupted file system. Add similar replacements of BUG_ON with EXT4_ERROR_INODE() ii ext4_create_inline_data() and ext4_inline_data_truncate().

Affected

39 ranges· showing 25
VendorProductVersion rangeFixed in
debiandebian_linux
debianlinux< linux 6.1.153-1 (bookworm)linux 6.1.153-1 (bookworm)
debianlinux-6.1< linux 6.1.153-1 (bookworm)linux 6.1.153-1 (bookworm)
linuxlinux
linuxlinux>= 67cf5b09a46f72e048501b84996f2f77bc42e947 < 8085a7324d8ec448c4a764af7853e19bbd64e17a8085a7324d8ec448c4a764af7853e19bbd64e17a
linuxlinux>= 67cf5b09a46f72e048501b84996f2f77bc42e947 < 1199a6399895f4767f0b9a68a6ff47c3f799b7c71199a6399895f4767f0b9a68a6ff47c3f799b7c7
linuxlinux>= 67cf5b09a46f72e048501b84996f2f77bc42e947 < 7f322c12df7aeed1755acd3c6fab48c7807795fb7f322c12df7aeed1755acd3c6fab48c7807795fb
linuxlinux>= 67cf5b09a46f72e048501b84996f2f77bc42e947 < 2817ac83cb4732597bf36853fe13ca616f4ee4e22817ac83cb4732597bf36853fe13ca616f4ee4e2
linuxlinux>= 67cf5b09a46f72e048501b84996f2f77bc42e947 < d960f4b793912f35e9d72bd9d1e90553063fcbf1d960f4b793912f35e9d72bd9d1e90553063fcbf1
linuxlinux>= 67cf5b09a46f72e048501b84996f2f77bc42e947 < 81e7e2e7ba07e7c8cdce43ccad2f91adbc5a919c81e7e2e7ba07e7c8cdce43ccad2f91adbc5a919c
linuxlinux>= 67cf5b09a46f72e048501b84996f2f77bc42e947 < 279c87ef7b9da34f65c2e4db586e730b667a6fb9279c87ef7b9da34f65c2e4db586e730b667a6fb9
linuxlinux>= 67cf5b09a46f72e048501b84996f2f77bc42e947 < 8a6f89d42e61788605722dd9faf98797c958a7e58a6f89d42e61788605722dd9faf98797c958a7e5
linuxlinux>= 67cf5b09a46f72e048501b84996f2f77bc42e947 < 099b847ccc6c1ad2f805d13cfbcc83f5b6d4bc42099b847ccc6c1ad2f805d13cfbcc83f5b6d4bc42
linuxlinux_kernel>= 0 < 5.10.244-15.10.244-1
linuxlinux_kernel>= 0 < 6.1.153-16.1.153-1
linuxlinux_kernel>= 0 < 6.12.43-16.12.43-1
linuxlinux_kernel>= 0 < 6.16.3-16.16.3-1
linuxlinux_kernel>= 0 < 5.15.0-163.1735.15.0-163.173
linuxlinux_kernel>= 0 < 6.8.0-100.1006.8.0-100.100
linuxlinux_kernel>= 3.8 < 5.4.2975.4.297
linuxlinux_kernel>= 5.11 < 5.15.1905.15.190
linuxlinux_kernel>= 5.16 < 6.1.1496.1.149
linuxlinux_kernel>= 5.5 < 5.10.2415.10.241
linuxlinux_kernel>= 6.13 < 6.15.116.15.11
linuxlinux_kernel>= 6.16 < 6.16.26.16.2

CVSS provenance

nvdv3.15.5MEDIUMCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
osv5.5MEDIUM