Executive brief
A vulnerability in the Linux kernel's ext4 file system could allow a local user to crash the system. By providing a specially crafted, corrupted file system image, an attacker can trigger a kernel panic (system crash). This issue primarily affects the availability of the system and could be used in a denial-of-service attack.
Technical details
A vulnerability exists in the ext4 file system component of the Linux kernel due to improper handling of inconsistent inode flags. Specifically, the kernel would trigger a BUG_ON() assertion in ext4_update_inline_data() if an inode had the INLINE_DATA_FL flag set but lacked the corresponding 'system.data' extended attribute (xattr). This condition, which can be induced via a maliciously fuzzed file system image, results in a kernel panic. The fix replaces these fatal BUG_ON() calls with EXT4_ERROR_INODE(), which gracefully handles the inconsistency as a file system corruption error rather than crashing the entire operating system. The vulnerability is reachable via local mounting or interaction with a crafted ext4 image.
Affected products
- Linux Linux Kernel 3.8 to 5.4.297, 5.5 to 5.10.241, 5.11 to 5.15.190, 5.16 to 6.1.149, 6.2 to 6.6.103, 6.7 to 6.12.43, 6.13 to 6.15.11, 6.16 to 6.16.2
Timeline
- 2025-07-17: patched: Initial patch authored by Theodore Ts'o
- 2025-09-04: disclosed: CVE published
References
- https://git.kernel.org/stable/c/099b847ccc6c1ad2f805d13cfbcc83f5b6d4bc42
- https://git.kernel.org/stable/c/1199a6399895f4767f0b9a68a6ff47c3f799b7c7
- https://git.kernel.org/stable/c/279c87ef7b9da34f65c2e4db586e730b667a6fb9
- https://git.kernel.org/stable/c/2817ac83cb4732597bf36853fe13ca616f4ee4e2
- https://git.kernel.org/stable/c/7f322c12df7aeed1755acd3c6fab48c7807795fb
- https://git.kernel.org/stable/c/8085a7324d8ec448c4a764af7853e19bbd64e17a
- https://git.kernel.org/stable/c/81e7e2e7ba07e7c8cdce43ccad2f91adbc5a919c