cbcvebase.
CVE-2025-71105
published 2026-01-14

CVE-2025-71105: In the Linux kernel, the following vulnerability has been resolved: f2fs: use global inline_xattr_slab instead of per-sb slab cache As Hong Yun reported in…

PriorityP421medium5.5CVSS 3.1
AVLACLPRLUINSUCNINAH
EPSS
0.12%
2.4th percentile
In the Linux kernel, the following vulnerability has been resolved: f2fs: use global inline_xattr_slab instead of per-sb slab cache As Hong Yun reported in mailing list: loop7: detected capacity change from 0 to 131072 ------------[ cut here ]------------ kmem_cache of name 'f2fs_xattr_entry-7:7' already exists WARNING: CPU: 0 PID: 24426 at mm/slab_common.c:110 kmem_cache_sanity_check mm/slab_common.c:109 [inline] WARNING: CPU: 0 PID: 24426 at mm/slab_common.c:110 __kmem_cache_create_args+0xa6/0x320 mm/slab_common.c:307 CPU: 0 UID: 0 PID: 24426 Comm: syz.7.1370 Not tainted 6.17.0-rc4 #1 PREEMPT(full) Hardware name: QEMU Standard PC (i440FX + PIIX, 1996), BIOS 1.13.0-1ubuntu1.1 04/01/2014 RIP: 0010:kmem_cache_sanity_check mm/slab_common.c:109 [inline] RIP: 0010:__kmem_cache_create_args+0xa6/0x320 mm/slab_common.c:307 Call Trace: __kmem_cache_create include/linux/slab.h:353 [inline] f2fs_kmem_cache_create fs/f2fs/f2fs.h:2943 [inline] f2fs_init_xattr_caches+0xa5/0xe0 fs/f2fs/xattr.c:843 f2fs_fill_super+0x1645/0x2620 fs/f2fs/super.c:4918 get_tree_bdev_flags+0x1fb/0x260 fs/super.c:1692 vfs_get_tree+0x43/0x140 fs/super.c:1815 do_new_mount+0x201/0x550 fs/namespace.c:3808 do_mount fs/namespace.c:4136 [inline] __do_sys_mount fs/namespace.c:4347 [inline] __se_sys_mount+0x298/0x2f0 fs/namespace.c:4324 do_syscall_x64 arch/x86/entry/syscall_64.c:63 [inline] do_syscall_64+0x8e/0x3a0 arch/x86/entry/syscall_64.c:94 entry_SYSCALL_64_after_hwframe+0x76/0x7e The bug can be reproduced w/ below scripts: - mount /dev/vdb /mnt1 - mount /dev/vdc /mnt2 - umount /mnt1 - mounnt /dev/vdb /mnt1 The reason is if we created two slab caches, named f2fs_xattr_entry-7:3 and f2fs_xattr_entry-7:7, and they have the same slab size. Actually, slab system will only create one slab cache core structure which has slab name of "f2fs_xattr_entry-7:3", and two slab caches share the same structure and cache address. So, if we destroy f2fs_xattr_entry-7:3 cache w/ cache address, it will decrease reference

Affected

59 ranges· showing 25
VendorProductVersion rangeFixed in
debianlinux< linux 6.1.162-1 (bookworm)linux 6.1.162-1 (bookworm)
debianlinux-6.1< linux 6.1.162-1 (bookworm)linux 6.1.162-1 (bookworm)
linuxlinux
linuxlinux>= a999150f4fe3abbb7efd05411fd5b460be699943 < 93d30fe19660dec6bf1bd3d5c186c1c737b21aa593d30fe19660dec6bf1bd3d5c186c1c737b21aa5
linuxlinux>= a999150f4fe3abbb7efd05411fd5b460be699943 < 474cc3ed37436ddfd63cac8dbffe3b1e219e9100474cc3ed37436ddfd63cac8dbffe3b1e219e9100
linuxlinux>= a999150f4fe3abbb7efd05411fd5b460be699943 < 72ce19dfed162da6e430467333b2da70471d08a472ce19dfed162da6e430467333b2da70471d08a4
linuxlinux>= a999150f4fe3abbb7efd05411fd5b460be699943 < be4c3a3c6c2304a8fcd14095d18d26f0cc4e222abe4c3a3c6c2304a8fcd14095d18d26f0cc4e222a
linuxlinux>= a999150f4fe3abbb7efd05411fd5b460be699943 < 1eb0b130196bcbc56c5c80c83139fa70c0aa82c51eb0b130196bcbc56c5c80c83139fa70c0aa82c5
linuxlinux>= a999150f4fe3abbb7efd05411fd5b460be699943 < e6d828eae00ec192e18c2ddaa2fd32050a96048ae6d828eae00ec192e18c2ddaa2fd32050a96048a
linuxlinux>= a999150f4fe3abbb7efd05411fd5b460be699943 < 1f27ef42bb0b7c0740c5616ec577ec188b8a1d051f27ef42bb0b7c0740c5616ec577ec188b8a1d05
linuxlinux_kernel
linuxlinux_kernel
linuxlinux_kernel>= 0 < 5.10.249-15.10.249-1
linuxlinux_kernel>= 0 < 6.1.162-16.1.162-1
linuxlinux_kernel>= 0 < 6.12.69-16.12.69-1
linuxlinux_kernel>= 0 < 6.18.3-16.18.3-1
linuxlinux_kernel>= 0 < 5.15.0-173.1835.15.0-173.183
linuxlinux_kernel>= 5.11 < 5.15.1985.15.198
linuxlinux_kernel>= 5.11.0 < 5.15.1985.15.198
linuxlinux_kernel>= 5.16 < 6.1.1606.1.160
linuxlinux_kernel>= 5.16.0 < 6.1.1606.1.160
linuxlinux_kernel>= 5.7.0 < 5.10.2485.10.248
linuxlinux_kernel>= 5.7.1 < 5.10.2485.10.248
linuxlinux_kernel>= 6.13 < 6.18.36.18.3
linuxlinux_kernel>= 6.13.0 < 6.18.36.18.3

CVSS provenance

nvdv3.15.5MEDIUMCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
osv7.8HIGH
vendor_ubuntu7.8HIGH
vendor_debian5.5MEDIUM
vendor_redhat5.5MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.