CVE-2025-22121
Vulnerability Summary
Timeline
Description
In the Linux kernel, the following vulnerability has been resolved: ext4: fix out-of-bound read in ext4_xattr_inode_dec_ref_all() There's issue as follows: BUG: KASAN: use-after-free in ext4_xattr_inode_dec_ref_all+0x6ff/0x790 Read of size 4 at addr ffff88807b003000 by task syz-executor.0/15172 CPU: 3 PID: 15172 Comm: syz-executor.0 Call Trace: __dump_stack lib/dump_stack.c:82 [inline] dump_stack+0xbe/0xfd lib/dump_stack.c:123 print_address_description.constprop.0+0x1e/0x280 mm/kasan/report.c:400 __kasan_report.cold+0x6c/0x84 mm/kasan/report.c:560 kasan_report+0x3a/0x50 mm/kasan/report.c:585 ext4_xattr_inode_dec_ref_all+0x6ff/0x790 fs/ext4/xattr.c:1137 ext4_xattr_delete_inode+0x4c7/0xda0 fs/ext4/xattr.c:2896 ext4_evict_inode+0xb3b/0x1670 fs/ext4/inode.c:323 evict+0x39f/0x880 fs/inode.c:622 iput_final fs/inode.c:1746 [inline] iput fs/inode.c:1772 [inline] iput+0x525/0x6c0 fs/inode.c:1758 ext4_orphan_cleanup fs/ext4/super.c:3298 [inline] ext4_fill_super+0x8c57/0xba40 fs/ext4/super.c:5300 mount_bdev+0x355/0x410 fs/super.c:1446 legacy_get_tree+0xfe/0x220 fs/fs_context.c:611 vfs_get_tree+0x8d/0x2f0 fs/super.c:1576 do_new_mount fs/namespace.c:2983 [inline] path_mount+0x119a/0x1ad0 fs/namespace.c:3316 do_mount+0xfc/0x110 fs/namespace.c:3329 __do_sys_mount fs/namespace.c:3540 [inline] __se_sys_mount+0x219/0x2e0 fs/namespace.c:3514 do_syscall_64+0x33/0x40 arch/x86/entry/common.c:46 entry_SYSCALL_64_after_hwframe+0x67/0xd1 Memory state around the buggy address: ffff88807b002f00: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 ffff88807b002f80: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 >ffff88807b003000: ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ^ ffff88807b003080: ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ffff88807b003100: ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff Above issue happens as ext4_xattr_delete_inode() isn't check xattr is valid if xattr is in inode. To solve above issue call xattr_check_inode() check if xattr if valid in inode. In fact, we can directly verify in ext4_iget_extra_inode(), so that there is no divergent verification.
CVSS Metrics
- v4.0•HIGH•Score: 7.1CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N
- v3.1•HIGH•Score: 7.1CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H
- v3.1•HIGH•Score: 8.4CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
EPSS Trends
Current EPSS score: 0.21%• Percentile: 11%
Techniques & Countermeasures
- CWE-125•Out-of-bounds Read
The product reads data past the end, or before the beginning, of the intended buffer.
Affected Systems
- chainguard•linux-aws-6.12
< 6.12.77-r1 | < 6.12.60-r4 | < 6.12.74-r1 | < 6.12.78-r0 | < 6.12.65-r2 | < 6.12.65-r0 | < 6.12.66-r0 | < 6.12.62-r1 | < 6.12.68-r1 | < 6.12.77-r0 | < 6.12.71-r0 | < 6.12.63-r0 | < 6.12.76-r0 | < 6.12.77-r2 | < 6.12.70-r0 | < 6.12.62-r0 | < 6.12.80-r0 | < 6.12.72-r1 | < 6.12.74-r0 | < 6.12.57-r2 | < 6.12.62-r2 | < 6.12.67-r0 | < 6.12.68-r0 | < 6.12.69-r0 | < 6.12.65-r1 | < 6.12.72-r0
- chainguard•linux-azure-6.12
< 6.12.60-r3 | < 6.12.68-r0 | < 6.12.77-r0 | < 6.12.65-r3 | < 6.12.76-r0 | < 6.12.67-r0 | < 6.12.72-r0 | < 6.12.65-r2 | < 6.12.57-r2 | < 6.12.78-r0 | < 6.12.77-r2 | < 6.12.66-r0 | < 6.12.74-r0 | < 6.12.62-r0 | < 6.12.69-r0 | < 6.12.70-r0 | < 6.12.60-r4 | < 6.12.63-r0 | < 6.12.62-r2 | < 6.12.65-r1 | < 6.12.77-r1 | < 6.12.65-r4 | < 6.12.74-r1 | < 6.12.80-r0 | < 6.12.62-r1 | < 6.12.71-r0
- chainguard•linux-gcp-6.12
< 6.12.74-r0 | < 6.12.74-r1 | < 6.12.60-r4 | < 6.12.68-r0 | < 6.12.60-r3 | < 6.12.65-r0 | < 6.12.78-r0 | < 6.12.62-r0 | < 6.12.67-r0 | < 6.12.65-r1 | < 6.12.65-r2 | < 6.12.77-r1 | < 6.12.77-r2 | < 6.12.71-r0 | < 6.12.57-r2 | < 6.12.80-r0 | < 6.12.62-r1 | < 6.12.76-r0 | < 6.12.62-r2 | < 6.12.69-r0 | < 6.12.77-r0 | < 6.12.63-r0 | < 6.12.72-r0 | < 6.12.70-r0 | < 6.12.66-r0 | < 6.12.68-r1
- chainguard•linux-qemu-6.12
< 6.12.74-r1 | < 6.12.69-r0 | < 6.12.67-r0 | < 6.12.76-r0 | < 6.12.66-r0 | < 6.12.72-r0 | < 6.12.74-r0 | < 6.12.78-r0 | < 6.12.65-r1 | < 6.12.77-r0 | < 6.12.71-r0 | < 6.12.77-r1 | < 6.12.68-r0 | < 6.12.70-r0 | < 6.12.80-r0 | < 6.12.65-r2 | < 6.12.77-r2
- chainguard•linux-vmware-6.12
< 6.12.70-r0 | < 6.12.69-r0 | < 6.12.68-r1 | < 6.12.77-r2 | < 6.12.74-r1 | < 6.12.72-r0 | < 6.12.77-r0 | < 6.12.65-r2 | < 6.12.71-r0 | < 6.12.67-r0 | < 6.12.65-r1 | < 6.12.76-r0 | < 6.12.66-r0 | < 6.12.68-r0 | < 6.12.80-r0 | < 6.12.78-r0 | < 6.12.77-r1 | < 6.12.74-r0
- debian•linux
< 5.10.249-1 | < 6.1.162-1 | < 6.12.63-1 | < 6.16.3-1
- debian•linux-6.1
< 6.1.162-1~deb11u1
- ubuntu•linux
all | < 5.15.0-173.183 | < 6.8.0-106.106
- ubuntu•linux-allwinner-5.19
all
- ubuntu•linux-aws
all | < 5.15.0-1103.110 | < 6.8.0-1050.53
- ubuntu•linux-aws-5.0
all
- ubuntu•linux-aws-5.11
all
- ubuntu•linux-aws-5.13
all
- ubuntu•linux-aws-5.15
< 5.15.0-1103.110~20.04.1
- ubuntu•linux-aws-5.19
all
- ubuntu•linux-aws-5.3
all
- ubuntu•linux-aws-5.4
all
- ubuntu•linux-aws-5.8
all
- ubuntu•linux-aws-6.2
all
- ubuntu•linux-aws-6.5
all
- ubuntu•linux-aws-6.8
< 6.8.0-1050.53~22.04.1
- ubuntu•linux-aws-fips
all | < 5.15.0-1103.110+fips1 | < 6.8.0-1050.53+fips1
- ubuntu•linux-aws-hwe
all
- ubuntu•linux-azure
all | all | < 5.15.0-1109.118 | < 6.8.0-1051.57
- ubuntu•linux-azure-4.15
all
- ubuntu•linux-azure-5.11
all
- ubuntu•linux-azure-5.13
all
- ubuntu•linux-azure-5.15
< 5.15.0-1110.119~20.04.1
- ubuntu•linux-azure-5.19
all
- ubuntu•linux-azure-5.3
all
- ubuntu•linux-azure-5.4
all
- ubuntu•linux-azure-5.8
all
- ubuntu•linux-azure-6.11
all
- ubuntu•linux-azure-6.2
all
- ubuntu•linux-azure-6.5
all
- ubuntu•linux-azure-6.8
< 6.8.0-1051.57~22.04.1
- ubuntu•linux-azure-edge
all
- ubuntu•linux-azure-fde
all | all | all | all
- ubuntu•linux-azure-fde-5.19
all
- ubuntu•linux-azure-fde-6.2
all
- ubuntu•linux-azure-fde-6.8
all
- ubuntu•linux-azure-fips
all | < 5.15.0-1109.118+fips1 | < 6.8.0-1052.58+fips1
- ubuntu•linux-azure-nvidia
all
- ubuntu•linux-bluefield
all | all | < 5.15.0-1086.88 | < 6.8.0-1017.21
- ubuntu•linux-fips
all | < 5.15.0-173.183+fips1 | < 6.8.0-106.106+fips1
- ubuntu•linux-gcp
all | all | < 5.15.0-1103.112 | < 6.8.0-1052.55
- ubuntu•linux-gcp-4.15
all
- ubuntu•linux-gcp-5.11
all
- ubuntu•linux-gcp-5.13
all
- ubuntu•linux-gcp-5.15
< 5.15.0-1103.112~20.04.1
Showing first 50 affected entries in server-rendered view.
References (38)
- https://git.kernel.org/stable/c/27202452b0bc942fdc3db72a44c4dcdab96d5b56
- https://git.kernel.org/stable/c/b374e9ecc92aaa7fb2ab221ee3ff5451118ab566
- https://git.kernel.org/stable/c/c000a8a9b5343a5ef867df173c6349672dacbd0f
- https://git.kernel.org/stable/c/3c591353956ffcace2cc74d09930774afed60619
- https://git.kernel.org/stable/c/098927a13fd918bd7c64c2de905350a1ad7b4a3a
- https://git.kernel.org/stable/c/0c8fbb6ffb3c8f5164572ca88e4ccb6cd6a41ca8
- https://git.kernel.org/stable/c/5701875f9609b000d91351eaa6bfd97fe2f157f4
- https://cert-portal.siemens.com/productcert/html/ssa-019113.html
- https://ubuntu.com/security/CVE-2025-22121
- https://www.cve.org/CVERecord?id=CVE-2025-22121
- https://git.kernel.org/linus/5701875f9609b000d91351eaa6bfd97fe2f157f4
- https://ubuntu.com/security/notices/USN-7594-1
- https://ubuntu.com/security/notices/USN-7594-2
- https://ubuntu.com/security/notices/USN-7594-3
- https://ubuntu.com/security/notices/USN-8095-1
- https://ubuntu.com/security/notices/USN-8096-1
- https://ubuntu.com/security/notices/USN-8100-1
- https://ubuntu.com/security/notices/USN-8095-2
- https://ubuntu.com/security/notices/USN-8096-2
- https://ubuntu.com/security/notices/USN-8095-3
- https://ubuntu.com/security/notices/USN-8096-3
- https://ubuntu.com/security/notices/USN-8096-4
- https://ubuntu.com/security/notices/USN-8116-1
- https://ubuntu.com/security/notices/USN-8095-4
- https://ubuntu.com/security/notices/USN-8096-5
- https://ubuntu.com/security/notices/USN-8125-1
- https://ubuntu.com/security/notices/USN-8126-1
- https://ubuntu.com/security/notices/USN-8095-5
- https://ubuntu.com/security/notices/USN-8141-1
- https://ubuntu.com/security/notices/USN-8163-1
- https://ubuntu.com/security/notices/USN-8165-1
- https://ubuntu.com/security/notices/USN-8163-2
- https://ubuntu.com/security/notices/USN-8243-1
- https://ubuntu.com/security/notices/USN-8261-1
- https://security-tracker.debian.org/tracker/CVE-2025-22121
- https://github.com/CVEProject/cvelistV5/tree/main/cves/2025/22xxx/CVE-2025-22121.json
- https://nvd.nist.gov/vuln/detail/CVE-2025-22121
- https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git