cbcvebase.
CVE-2025-40179
published 2025-11-12

CVE-2025-40179: In the Linux kernel, the following vulnerability has been resolved: ext4: verify orphan file size is not too big In principle orphan file can be arbitrarily…

PriorityP422high7.8
EPSS
0.20%
10.3th percentile
In the Linux kernel, the following vulnerability has been resolved: ext4: verify orphan file size is not too big In principle orphan file can be arbitrarily large. However orphan replay needs to traverse it all and we also pin all its buffers in memory. Thus filesystems with absurdly large orphan files can lead to big amounts of memory consumed. Limit orphan file size to a sane value and also use kvmalloc() for allocating array of block descriptor structures to avoid large order allocations for sane but large orphan files.

Affected

27 ranges· showing 25
VendorProductVersion rangeFixed in
debianlinux< linux 6.1.158-1 (bookworm)linux 6.1.158-1 (bookworm)
debianlinux-6.1< linux 6.1.158-1 (bookworm)linux 6.1.158-1 (bookworm)
linuxlinux
linuxlinux>= 02f310fcf47fa9311d6ba2946a8d19e7d7d11f37 < 95a21611b14ae0a401720645245a8db16f04099595a21611b14ae0a401720645245a8db16f040995
linuxlinux>= 02f310fcf47fa9311d6ba2946a8d19e7d7d11f37 < 566a1d6084563bd07433025aa23bcea4427de107566a1d6084563bd07433025aa23bcea4427de107
linuxlinux>= 02f310fcf47fa9311d6ba2946a8d19e7d7d11f37 < 304fc34ff6fc8261138fd81f119e024ac3a129e9304fc34ff6fc8261138fd81f119e024ac3a129e9
linuxlinux>= 02f310fcf47fa9311d6ba2946a8d19e7d7d11f37 < a2d803fab8a6c6a874277cb80156dc114db91921a2d803fab8a6c6a874277cb80156dc114db91921
linuxlinux>= 02f310fcf47fa9311d6ba2946a8d19e7d7d11f37 < 2b9da798ff0f4d026c5f0f815047393ebe7d88592b9da798ff0f4d026c5f0f815047393ebe7d8859
linuxlinux>= 02f310fcf47fa9311d6ba2946a8d19e7d7d11f37 < 0a6ce20c156442a4ce2a404747bb0fb05d54eeb30a6ce20c156442a4ce2a404747bb0fb05d54eeb3
linuxlinux_kernel>= 0 < 6.1.158-16.1.158-1
linuxlinux_kernel>= 0 < 6.12.57-16.12.57-1
linuxlinux_kernel>= 0 < 6.17.6-16.17.6-1
linuxlinux_kernel>= 0 < 5.15.0-170.1805.15.0-170.180
linuxlinux_kernel>= 0 < 6.8.0-106.1066.8.0-106.106
linuxlinux_kernel>= 0 < 6.17.0-14.146.17.0-14.14
linuxlinux_kernel>= 5.15.0 < 5.15.1955.15.195
linuxlinux_kernel>= 5.16.0 < 6.1.1576.1.157
linuxlinux_kernel>= 6.13.0 < 6.17.46.17.4
linuxlinux_kernel>= 6.2.0 < 6.6.1136.6.113
linuxlinux_kernel>= 6.7.0 < 6.12.546.12.54
msrcazl3_kernel_6.6.112.1-2_on_azure_linux_3.0
ubuntulinux-aws
ubuntulinux-azure-5.15
ubuntulinux-intel-iotg-5.15
ubuntulinux-oracle

CVSS provenance

osv7.8HIGH
vendor_ubuntu7.8HIGH
vendor_msrc5.5MEDIUM
vendor_redhat4.7MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.