Junglewise Threat Intelligence

CVE-2025-38701: Linux Kernel ext4 reachable assertion via fuzzed inline data xattr

CVE-2025-38701 · Severity: medium · CVSS 5.5 · Published 2025-09-04

Technologies: Linux Kernel. Vendors: Linux.

Executive brief

A vulnerability in the Linux kernel's ext4 file system could allow a local user to crash the system. By providing a specially crafted, corrupted file system image, an attacker can trigger a kernel panic (system crash). This issue primarily affects the availability of the system and could be used in a denial-of-service attack.

Technical details

A vulnerability exists in the ext4 file system component of the Linux kernel due to improper handling of inconsistent inode flags. Specifically, the kernel would trigger a BUG_ON() assertion in ext4_update_inline_data() if an inode had the INLINE_DATA_FL flag set but lacked the corresponding 'system.data' extended attribute (xattr). This condition, which can be induced via a maliciously fuzzed file system image, results in a kernel panic. The fix replaces these fatal BUG_ON() calls with EXT4_ERROR_INODE(), which gracefully handles the inconsistency as a file system corruption error rather than crashing the entire operating system. The vulnerability is reachable via local mounting or interaction with a crafted ext4 image.

Affected products

  • Linux Linux Kernel 3.8 to 5.4.297, 5.5 to 5.10.241, 5.11 to 5.15.190, 5.16 to 6.1.149, 6.2 to 6.6.103, 6.7 to 6.12.43, 6.13 to 6.15.11, 6.16 to 6.16.2

Timeline

  • 2025-07-17: patched: Initial patch authored by Theodore Ts'o
  • 2025-09-04: disclosed: CVE published

References

Related threats