CVE-2025-22121

Aliases:UBUNTU-CVE-2025-22121DEBIAN-CVE-2025-22121CGA-2887-gf3g-jq4wCGA-28xg-wq74-hmw9CGA-2v25-8j6m-6jgmCGA-2vmv-6xgv-9wvwCGA-328v-x7mr-xmpmCGA-3377-4f7f-crf4CGA-3f4r-xr2w-jcpfCGA-3gj3-cpjw-8rhxCGA-3j82-4c96-q47mCGA-424r-39fg-m32hCGA-43rc-5vrg-652jCGA-44p9-9rf9-2739CGA-4c32-f43v-p38cCGA-4cr7-cq5g-m4qxCGA-4r5x-58qc-4p2xCGA-4w35-v456-39xrCGA-4x59-8v73-25qhCGA-5c6c-rv4p-rwpwCGA-5jg7-rg8p-35j7CGA-5qqw-w7xm-58frCGA-6797-32x6-gw5hCGA-6fc4-9hp8-xr4rCGA-6wp4-ppfp-xjf9CGA-6wpc-w869-7fwxCGA-74hv-m98c-46f2CGA-7ffr-9jv6-qm73CGA-7hg2-cfxw-chw4CGA-7phq-483j-39fgCGA-7rhj-gq7f-75xfCGA-7wmg-c78j-r3jqCGA-825j-pm5w-2cgwCGA-84p4-wph9-g4r7CGA-85hx-vv4f-6j94CGA-865w-2637-p725CGA-88w5-2fw7-75jxCGA-8f76-49h3-vm56CGA-8h6p-55cm-ch6mCGA-8p4p-7xmh-8g2qCGA-982c-j3r8-q4rcCGA-9f8r-gpgq-46h3CGA-9vrq-vccr-9mr7CGA-9xw6-fgx4-w528CGA-c284-qmj7-xvv4CGA-c2p3-hmx2-frxwCGA-c8rr-mq9w-9rx4CGA-cq3p-8f6p-wqm8CGA-cvpc-96mg-gfj9CGA-cwm9-w36w-9w76CGA-cx92-mfc4-h7m7CGA-f4qh-f3cf-2rjcCGA-f743-rj2m-2hhcCGA-fj8h-33wx-hm53CGA-fm3j-gvhh-6r84CGA-fmvx-3v3r-pxj9CGA-fr86-m539-7rv7CGA-fwwx-9x5r-pw85CGA-g67w-4cp6-75j3CGA-g7pf-8mg8-4vh7CGA-gcmh-547j-fg26CGA-gmqw-h2xj-97xvCGA-gq3f-h87w-fw2rCGA-h4jh-wf5m-9493CGA-h5x5-r7vh-6ff3CGA-h6wq-3rx4-4m8xCGA-h72m-6rjw-923xCGA-h79p-jg6j-42v3CGA-j63c-chpq-qgm5CGA-j74p-2p25-62m7CGA-j8jm-2q9m-j494CGA-j97v-mjjx-r83fCGA-jc8r-pr34-39h8CGA-jcq3-cq7j-7cr4CGA-jjjm-w2rq-m7fjCGA-m35f-4298-64j3CGA-m825-49hc-435qCGA-m8cx-8fq3-9vxwCGA-m8xf-x6vj-9q23CGA-mp2w-2rr2-gpfrCGA-mr2w-x8c5-h4qxCGA-mrxv-xgcx-5rmvCGA-mx72-p6vh-5wf2CGA-p4c2-6xrr-x2fqCGA-p75r-qj55-jp9hCGA-pcfp-qqq8-h9gpCGA-ph3q-mc25-5hvqCGA-pj4w-3gc8-vc2mCGA-pv3c-5c7g-22rxCGA-q2mv-92g4-gv4xCGA-q58v-8rr6-fxvpCGA-q8rq-22g4-fg7gCGA-qjmp-v832-6cqjCGA-r3w7-r6x5-9gppCGA-r67q-f2rg-r92fCGA-r95w-4fm3-23wwCGA-rj8q-q488-3xw2CGA-rpc9-c872-9269CGA-rw2j-9gxv-cm9jCGA-v592-h5mr-36rqCGA-v69v-6v56-x8x9CGA-vfqj-956j-rghvCGA-vjp7-5v52-69f5CGA-vp9v-vr5x-j2pfCGA-vq7r-9p3v-4jr5CGA-vqxw-m98g-w923CGA-vrcw-r5m2-66wgCGA-w267-xjf2-f63jCGA-w2q8-5cqg-39rqCGA-w5w7-c4wm-hv39CGA-wh29-52jm-8r9gCGA-wqf7-36gm-9p2qCGA-wv8r-3j25-27cvCGA-wwg9-h939-mrj7CGA-wwh4-w42j-3cfqCGA-x5vf-c2qj-646rCGA-x8xg-4288-4m87CGA-xj48-p2v7-mmwxCGA-xv6q-j2hq-6q9mCGA-xx5v-xjj2-36ph
Advisory lineage Upstream: 0 Downstream: 46
Modified
Published: 16 Apr 2025, 14:13
Last modified:08 Sept 2026, 08:41

Vulnerability Summary

Overall Risk (default)
medium
34/100
CVSS Score
8.4 HIGH
v3.1 (cve.org)
EPSS Score
0.21% LOW
0% probability +0.18%
KEV
Not listed
Ransomware
No reports
Public exploits
None found
Dark Web
Not detected

Timeline

16 Apr 2025, 14:13
Published
Vulnerability first disclosed
08 Sept 2026, 08:41
Last Modified
Vulnerability information updated

Description

In the Linux kernel, the following vulnerability has been resolved: ext4: fix out-of-bound read in ext4_xattr_inode_dec_ref_all() There's issue as follows: BUG: KASAN: use-after-free in ext4_xattr_inode_dec_ref_all+0x6ff/0x790 Read of size 4 at addr ffff88807b003000 by task syz-executor.0/15172 CPU: 3 PID: 15172 Comm: syz-executor.0 Call Trace: __dump_stack lib/dump_stack.c:82 [inline] dump_stack+0xbe/0xfd lib/dump_stack.c:123 print_address_description.constprop.0+0x1e/0x280 mm/kasan/report.c:400 __kasan_report.cold+0x6c/0x84 mm/kasan/report.c:560 kasan_report+0x3a/0x50 mm/kasan/report.c:585 ext4_xattr_inode_dec_ref_all+0x6ff/0x790 fs/ext4/xattr.c:1137 ext4_xattr_delete_inode+0x4c7/0xda0 fs/ext4/xattr.c:2896 ext4_evict_inode+0xb3b/0x1670 fs/ext4/inode.c:323 evict+0x39f/0x880 fs/inode.c:622 iput_final fs/inode.c:1746 [inline] iput fs/inode.c:1772 [inline] iput+0x525/0x6c0 fs/inode.c:1758 ext4_orphan_cleanup fs/ext4/super.c:3298 [inline] ext4_fill_super+0x8c57/0xba40 fs/ext4/super.c:5300 mount_bdev+0x355/0x410 fs/super.c:1446 legacy_get_tree+0xfe/0x220 fs/fs_context.c:611 vfs_get_tree+0x8d/0x2f0 fs/super.c:1576 do_new_mount fs/namespace.c:2983 [inline] path_mount+0x119a/0x1ad0 fs/namespace.c:3316 do_mount+0xfc/0x110 fs/namespace.c:3329 __do_sys_mount fs/namespace.c:3540 [inline] __se_sys_mount+0x219/0x2e0 fs/namespace.c:3514 do_syscall_64+0x33/0x40 arch/x86/entry/common.c:46 entry_SYSCALL_64_after_hwframe+0x67/0xd1 Memory state around the buggy address: ffff88807b002f00: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 ffff88807b002f80: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 >ffff88807b003000: ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ^ ffff88807b003080: ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ffff88807b003100: ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff Above issue happens as ext4_xattr_delete_inode() isn't check xattr is valid if xattr is in inode. To solve above issue call xattr_check_inode() check if xattr if valid in inode. In fact, we can directly verify in ext4_iget_extra_inode(), so that there is no divergent verification.

CVSS Metrics

  • v4.0HIGHScore: 7.1CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N
  • v3.1HIGHScore: 7.1CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H
  • v3.1HIGHScore: 8.4CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

EPSS Trends

Current EPSS score: 0.21% Percentile: 11%

Techniques & Countermeasures

  • CWE-125Out-of-bounds Read

    The product reads data past the end, or before the beginning, of the intended buffer.

Affected Systems

  • chainguardlinux-aws-6.12

    < 6.12.77-r1 | < 6.12.60-r4 | < 6.12.74-r1 | < 6.12.78-r0 | < 6.12.65-r2 | < 6.12.65-r0 | < 6.12.66-r0 | < 6.12.62-r1 | < 6.12.68-r1 | < 6.12.77-r0 | < 6.12.71-r0 | < 6.12.63-r0 | < 6.12.76-r0 | < 6.12.77-r2 | < 6.12.70-r0 | < 6.12.62-r0 | < 6.12.80-r0 | < 6.12.72-r1 | < 6.12.74-r0 | < 6.12.57-r2 | < 6.12.62-r2 | < 6.12.67-r0 | < 6.12.68-r0 | < 6.12.69-r0 | < 6.12.65-r1 | < 6.12.72-r0

  • chainguardlinux-azure-6.12

    < 6.12.60-r3 | < 6.12.68-r0 | < 6.12.77-r0 | < 6.12.65-r3 | < 6.12.76-r0 | < 6.12.67-r0 | < 6.12.72-r0 | < 6.12.65-r2 | < 6.12.57-r2 | < 6.12.78-r0 | < 6.12.77-r2 | < 6.12.66-r0 | < 6.12.74-r0 | < 6.12.62-r0 | < 6.12.69-r0 | < 6.12.70-r0 | < 6.12.60-r4 | < 6.12.63-r0 | < 6.12.62-r2 | < 6.12.65-r1 | < 6.12.77-r1 | < 6.12.65-r4 | < 6.12.74-r1 | < 6.12.80-r0 | < 6.12.62-r1 | < 6.12.71-r0

  • chainguardlinux-gcp-6.12

    < 6.12.74-r0 | < 6.12.74-r1 | < 6.12.60-r4 | < 6.12.68-r0 | < 6.12.60-r3 | < 6.12.65-r0 | < 6.12.78-r0 | < 6.12.62-r0 | < 6.12.67-r0 | < 6.12.65-r1 | < 6.12.65-r2 | < 6.12.77-r1 | < 6.12.77-r2 | < 6.12.71-r0 | < 6.12.57-r2 | < 6.12.80-r0 | < 6.12.62-r1 | < 6.12.76-r0 | < 6.12.62-r2 | < 6.12.69-r0 | < 6.12.77-r0 | < 6.12.63-r0 | < 6.12.72-r0 | < 6.12.70-r0 | < 6.12.66-r0 | < 6.12.68-r1

  • chainguardlinux-qemu-6.12

    < 6.12.74-r1 | < 6.12.69-r0 | < 6.12.67-r0 | < 6.12.76-r0 | < 6.12.66-r0 | < 6.12.72-r0 | < 6.12.74-r0 | < 6.12.78-r0 | < 6.12.65-r1 | < 6.12.77-r0 | < 6.12.71-r0 | < 6.12.77-r1 | < 6.12.68-r0 | < 6.12.70-r0 | < 6.12.80-r0 | < 6.12.65-r2 | < 6.12.77-r2

  • chainguardlinux-vmware-6.12

    < 6.12.70-r0 | < 6.12.69-r0 | < 6.12.68-r1 | < 6.12.77-r2 | < 6.12.74-r1 | < 6.12.72-r0 | < 6.12.77-r0 | < 6.12.65-r2 | < 6.12.71-r0 | < 6.12.67-r0 | < 6.12.65-r1 | < 6.12.76-r0 | < 6.12.66-r0 | < 6.12.68-r0 | < 6.12.80-r0 | < 6.12.78-r0 | < 6.12.77-r1 | < 6.12.74-r0

  • debianlinux

    < 5.10.249-1 | < 6.1.162-1 | < 6.12.63-1 | < 6.16.3-1

  • debianlinux-6.1

    < 6.1.162-1~deb11u1

  • ubuntulinux

    all | < 5.15.0-173.183 | < 6.8.0-106.106

  • ubuntulinux-allwinner-5.19

    all

  • ubuntulinux-aws

    all | < 5.15.0-1103.110 | < 6.8.0-1050.53

  • ubuntulinux-aws-5.0

    all

  • ubuntulinux-aws-5.11

    all

  • ubuntulinux-aws-5.13

    all

  • ubuntulinux-aws-5.15

    < 5.15.0-1103.110~20.04.1

  • ubuntulinux-aws-5.19

    all

  • ubuntulinux-aws-5.3

    all

  • ubuntulinux-aws-5.4

    all

  • ubuntulinux-aws-5.8

    all

  • ubuntulinux-aws-6.2

    all

  • ubuntulinux-aws-6.5

    all

  • ubuntulinux-aws-6.8

    < 6.8.0-1050.53~22.04.1

  • ubuntulinux-aws-fips

    all | < 5.15.0-1103.110+fips1 | < 6.8.0-1050.53+fips1

  • ubuntulinux-aws-hwe

    all

  • ubuntulinux-azure

    all | all | < 5.15.0-1109.118 | < 6.8.0-1051.57

  • ubuntulinux-azure-4.15

    all

  • ubuntulinux-azure-5.11

    all

  • ubuntulinux-azure-5.13

    all

  • ubuntulinux-azure-5.15

    < 5.15.0-1110.119~20.04.1

  • ubuntulinux-azure-5.19

    all

  • ubuntulinux-azure-5.3

    all

  • ubuntulinux-azure-5.4

    all

  • ubuntulinux-azure-5.8

    all

  • ubuntulinux-azure-6.11

    all

  • ubuntulinux-azure-6.2

    all

  • ubuntulinux-azure-6.5

    all

  • ubuntulinux-azure-6.8

    < 6.8.0-1051.57~22.04.1

  • ubuntulinux-azure-edge

    all

  • ubuntulinux-azure-fde

    all | all | all | all

  • ubuntulinux-azure-fde-5.19

    all

  • ubuntulinux-azure-fde-6.2

    all

  • ubuntulinux-azure-fde-6.8

    all

  • ubuntulinux-azure-fips

    all | < 5.15.0-1109.118+fips1 | < 6.8.0-1052.58+fips1

  • ubuntulinux-azure-nvidia

    all

  • ubuntulinux-bluefield

    all | all | < 5.15.0-1086.88 | < 6.8.0-1017.21

  • ubuntulinux-fips

    all | < 5.15.0-173.183+fips1 | < 6.8.0-106.106+fips1

  • ubuntulinux-gcp

    all | all | < 5.15.0-1103.112 | < 6.8.0-1052.55

  • ubuntulinux-gcp-4.15

    all

  • ubuntulinux-gcp-5.11

    all

  • ubuntulinux-gcp-5.13

    all

  • ubuntulinux-gcp-5.15

    < 5.15.0-1103.112~20.04.1

Showing first 50 affected entries in server-rendered view.

References (38)