CVE-2025-71161

Aliases:UBUNTU-CVE-2025-71161DEBIAN-CVE-2025-71161CGA-38jh-35p3-q3v6CGA-3jw5-wxh9-xh86CGA-3rf4-x6ff-mxvgCGA-44xg-f2wr-76h3CGA-4jh4-8h9v-mwcmCGA-53fq-cmwj-p4gmCGA-55x8-5ppv-xm4wCGA-58vv-w995-x8w8CGA-5r57-9g4w-3952CGA-5rx8-r9cm-5cccCGA-6rw5-cv3x-cfpxCGA-7j9f-6vm5-jqj7CGA-843h-92mc-453vCGA-87r7-4xwf-fwjgCGA-8cw4-r3r4-jj25CGA-8hff-vpgh-jxx2CGA-8jqw-j8vp-mcrcCGA-96w7-c24c-m8r8CGA-9c2p-fw5g-8x6jCGA-9w49-4h8f-267mCGA-c4q2-wfhm-vgvxCGA-c6c4-36h9-7vx3CGA-c9xf-mghf-cjhhCGA-cfwf-hh5p-92cqCGA-cqcw-vq3j-f5q7CGA-cw2w-m4v9-g2hmCGA-cxcm-8hgv-425hCGA-frc8-c2fv-qf8fCGA-fxmp-xq89-54mvCGA-gjwj-pf8p-5r29CGA-gwww-jr34-7jvcCGA-h2hh-v26h-46wgCGA-pfvq-8hfq-p338CGA-qcgr-c7fg-fq73CGA-qrc2-q5v6-7wghCGA-r4p3-g7c5-9vp6CGA-w64m-hr99-v7xfCGA-w723-pm57-f848CGA-wmwx-hqjx-wmwfCGA-wqwg-ffxr-488h
Modified
Published: 23 Jan 2026, 15:23
Last modified:08 Sept 2026, 08:44

Vulnerability Summary

Overall Risk (default)
medium
30/100
CVSS Score
7.5 HIGH
v3.1 (cve.org)
EPSS Score
0.35% LOW
0% probability +0.34%
KEV
Not listed
Ransomware
No reports
Public exploits
None found
Dark Web
Not detected

Timeline

23 Jan 2026, 15:23
Published
Vulnerability first disclosed
08 Sept 2026, 08:44
Last Modified
Vulnerability information updated

Description

In the Linux kernel, the following vulnerability has been resolved: dm-verity: disable recursive forward error correction There are two problems with the recursive correction: 1. It may cause denial-of-service. In fec_read_bufs, there is a loop that has 253 iterations. For each iteration, we may call verity_hash_for_block recursively. There is a limit of 4 nested recursions - that means that there may be at most 253^4 (4 billion) iterations. Red Hat QE team actually created an image that pushes dm-verity to this limit - and this image just makes the udev-worker process get stuck in the 'D' state. 2. It doesn't work. In fec_read_bufs we store data into the variable "fio->bufs", but fio bufs is shared between recursive invocations, if "verity_hash_for_block" invoked correction recursively, it would overwrite partially filled fio->bufs.

CVSS Metrics

  • v3.1MEDIUMScore: 5.5CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
  • v3.1HIGHScore: 7.5CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

EPSS Trends

Current EPSS score: 0.35% Percentile: 29%

Techniques & Countermeasures

  • CWE-193Off-by-one Error

    A product calculates or uses an incorrect maximum or minimum value that is 1 more, or 1 less, than the correct value.

Affected Systems

  • chainguardlinux-aws-6.12

    < 6.12.77-r1 | < 6.12.74-r1 | < 6.12.78-r0 | < 6.12.76-r0 | < 6.12.80-r0 | < 6.12.77-r0 | < 6.12.77-r2

  • chainguardlinux-azure-6.12

    < 6.12.77-r2 | < 6.12.74-r1 | < 6.12.80-r0 | < 6.12.76-r0 | < 6.12.78-r0 | < 6.12.77-r1 | < 6.12.77-r0

  • chainguardlinux-gcp-6.12

    < 6.12.76-r0 | < 6.12.77-r0 | < 6.12.77-r1 | < 6.12.78-r0 | < 6.12.74-r1 | < 6.12.77-r2 | < 6.12.80-r0

  • chainguardlinux-qemu-6.12

    < 6.12.77-r0 | < 6.12.80-r0 | < 6.12.74-r1 | < 6.12.78-r0 | < 6.12.76-r0 | < 6.12.77-r1 | < 6.12.77-r2

  • chainguardlinux-vmware-6.12

    < 6.12.78-r0 | < 6.12.77-r1 | < 6.12.74-r1 | < 6.12.77-r2 | < 6.12.76-r0 | < 6.12.77-r0 | < 6.12.80-r0

  • debianlinux

    all | < 6.1.170-1 | < 6.12.85-1 | < 6.18.8-1

  • debianlinux-6.1

    < 6.1.170-1~deb11u1

  • ubuntulinux

    all | < 5.15.0-186.196 | < 6.8.0-136.136 | all

  • ubuntulinux-allwinner-5.19

    all

  • ubuntulinux-aws

    all | < 5.15.0-1112.119 | < 6.8.0-1061.64 | all

  • ubuntulinux-aws-5.0

    all

  • ubuntulinux-aws-5.11

    all

  • ubuntulinux-aws-5.13

    all

  • ubuntulinux-aws-5.15

    < 5.15.0-1112.119~20.04.1

  • ubuntulinux-aws-5.19

    all

  • ubuntulinux-aws-5.3

    all

  • ubuntulinux-aws-5.4

    all

  • ubuntulinux-aws-5.8

    all

  • ubuntulinux-aws-6.14

    all

  • ubuntulinux-aws-6.17

    all

  • ubuntulinux-aws-6.2

    all

  • ubuntulinux-aws-6.5

    all

  • ubuntulinux-aws-6.8

    < 6.8.0-1061.64~22.04.1

  • ubuntulinux-aws-fips

    all | < 5.15.0-1112.119+fips1 | < 6.8.0-1061.64+fips1

  • ubuntulinux-aws-hwe

    all

  • ubuntulinux-azure

    all | all | < 5.15.0-1117.126 | < 6.8.0-1063.71 | all

  • ubuntulinux-azure-4.15

    all

  • ubuntulinux-azure-5.11

    all

  • ubuntulinux-azure-5.13

    all

  • ubuntulinux-azure-5.15

    < 5.15.0-1117.126~20.04.1

  • ubuntulinux-azure-5.19

    all

  • ubuntulinux-azure-5.3

    all

  • ubuntulinux-azure-5.4

    all

  • ubuntulinux-azure-5.8

    all

  • ubuntulinux-azure-6.11

    all

  • ubuntulinux-azure-6.14

    all

  • ubuntulinux-azure-6.17

    < 6.17.0-1021.21~24.04.1

  • ubuntulinux-azure-6.2

    all

  • ubuntulinux-azure-6.5

    all

  • ubuntulinux-azure-6.8

    < 6.8.0-1063.71~22.04.1

  • ubuntulinux-azure-edge

    all

  • ubuntulinux-azure-fde

    all | < 5.15.0-1117.126 | < 6.8.0-1062.69 | all

  • ubuntulinux-azure-fde-5.15

    < 5.15.0-1117.126~20.04.2

  • ubuntulinux-azure-fde-5.19

    all

  • ubuntulinux-azure-fde-6.14

    all

  • ubuntulinux-azure-fde-6.2

    all

  • ubuntulinux-azure-fde-6.8

    < 6.8.0-1062.69~22.04.1

  • ubuntulinux-azure-fips

    all | < 5.15.0-1117.126+fips1 | < 6.8.0-1063.71+fips2

  • ubuntulinux-azure-nvidia

    all

  • ubuntulinux-azure-nvidia-6.14

    all

Showing first 50 affected entries in server-rendered view.

References (47)