cbcvebase.
CVE-2025-40150
published 2025-11-12

CVE-2025-40150: In the Linux kernel, the following vulnerability has been resolved: f2fs: fix to avoid migrating empty section It reports a bug from device w/ zufs: F2FS-fs…

PriorityP422medium7.5
EPSS
0.24%
15.2th percentile
In the Linux kernel, the following vulnerability has been resolved: f2fs: fix to avoid migrating empty section It reports a bug from device w/ zufs: F2FS-fs (dm-64): Inconsistent segment (173822) type [1, 0] in SSA and SIT F2FS-fs (dm-64): Stopped filesystem due to reason: 4 Thread A Thread B - f2fs_expand_inode_data - f2fs_allocate_pinning_section - f2fs_gc_range - do_garbage_collect w/ segno #x - writepage - f2fs_allocate_data_block - new_curseg - allocate segno #x The root cause is: fallocate on pinning file may race w/ block allocation as above, result in do_garbage_collect() from fallocate() may migrate segment which is just allocated by a log, the log will update segment type in its in-memory structure, however GC will get segment type from on-disk SSA block, once segment type changes by log, we can detect such inconsistency, then shutdown filesystem. In this case, on-disk SSA shows type of segno #173822 is 1 (SUM_TYPE_NODE), however segno #173822 was just allocated as data type segment, so in-memory SIT shows type of segno #173822 is 0 (SUM_TYPE_DATA). Change as below to fix this issue: - check whether current section is empty before gc - add sanity checks on do_garbage_collect() to avoid any race case, result in migrating segment used by log. - btw, it fixes misc issue in printed logs: "SSA and SIT" -> "SIT and SSA".

Affected

35 ranges· showing 25
VendorProductVersion rangeFixed in
debianlinux< linux 6.17.6-1 (forky)linux 6.17.6-1 (forky)
linuxlinux
linuxlinux>= 40d76c393cca83938b11eb7ca8983aa3cd0ed69b < db489778e6f2a4034c2cd26fadda2796eba24dcddb489778e6f2a4034c2cd26fadda2796eba24dcd
linuxlinux>= 6.6.33 < 6.6.1306.6.130
linuxlinux>= 9703d69d9d153bb230711d0d577454552aeb13d4 < 25d2dc669f2a7e48b335d1cb07139f2ffc9fe5df25d2dc669f2a7e48b335d1cb07139f2ffc9fe5df
linuxlinux>= 9703d69d9d153bb230711d0d577454552aeb13d4 < eec1589be36fcf7440755703e4faeee2c01e360beec1589be36fcf7440755703e4faeee2c01e360b
linuxlinux>= 9703d69d9d153bb230711d0d577454552aeb13d4 < d625a2b08c089397d3a03bff13fa8645e4ec7a01d625a2b08c089397d3a03bff13fa8645e4ec7a01
linuxlinux_kernel>= 0 < 6.17.6-16.17.6-1
linuxlinux_kernel>= 0 < 6.6.1306.6.130
linuxlinux_kernel>= 0 < 6.17.0-14.146.17.0-14.14
linuxlinux_kernel>= 6.7.0 < 6.12.786.12.78
linuxlinux_kernel>= 6.9.0 < 6.17.36.17.3
ubuntulinux
ubuntulinux-aws
ubuntulinux-azure
ubuntulinux-azure-6.8
ubuntulinux-azure-fde
ubuntulinux-azure-fde-6.8
ubuntulinux-azure-fips
ubuntulinux-fips
ubuntulinux-gcp
ubuntulinux-gcp-6.8
ubuntulinux-gcp-fips
ubuntulinux-gke
ubuntulinux-gkeop

CVSS provenance

vendor_oracle7.5MEDIUM
vendor_ubuntu2.0LOW
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.