cbcvebase.
CVE-2025-68251
published 2025-12-16

CVE-2025-68251: In the Linux kernel, the following vulnerability has been resolved: erofs: avoid infinite loops due to corrupted subpage compact indexes Robert reported an…

PriorityP422low5.5
EPSS
0.16%
6.0th percentile
In the Linux kernel, the following vulnerability has been resolved: erofs: avoid infinite loops due to corrupted subpage compact indexes Robert reported an infinite loop observed by two crafted images. The root cause is that `clusterofs` can be larger than `lclustersize` for !NONHEAD `lclusters` in corrupted subpage compact indexes, e.g.: blocksize = lclustersize = 512 lcn = 6 clusterofs = 515 Move the corresponding check for full compress indexes to `z_erofs_load_lcluster_from_disk()` to also cover subpage compact compress indexes. It also fixes the position of `m->type >= Z_EROFS_LCLUSTER_TYPE_MAX` check, since it should be placed right after `z_erofs_load_{compact,full}_lcluster()`.

Affected

14 ranges
VendorProductVersion rangeFixed in
debianlinux< linux 6.17.6-1 (forky)linux 6.17.6-1 (forky)
linuxlinux
linuxlinux
linuxlinux
linuxlinux>= 6.6.16 < 6.76.7
linuxlinux>= 6.7.4 < 6.86.8
linuxlinux>= 8d2517aaeea3ab8651bb517bca8f3c8664d318ea < dbfac1b85d0753996ddfef636934d431b588dd1fdbfac1b85d0753996ddfef636934d431b588dd1f
linuxlinux>= 8d2517aaeea3ab8651bb517bca8f3c8664d318ea < 8675447a8794983f2b7e694b378112772c17635e8675447a8794983f2b7e694b378112772c17635e
linuxlinux>= 8d2517aaeea3ab8651bb517bca8f3c8664d318ea < e13d315ae077bb7c3c6027cc292401bc0f4ec683e13d315ae077bb7c3c6027cc292401bc0f4ec683
linuxlinux_kernel>= 0 < 6.17.6-16.17.6-1
linuxlinux_kernel>= 0 < 6.17.0-14.146.17.0-14.14
linuxlinux_kernel>= 6.8.0 < 6.17.66.17.6
ubuntulinux-aws
ubuntulinux-oracle
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.