Executive brief
A vulnerability in the Linux kernel's ext4 file system could allow a system crash or potential data corruption when handling specially crafted, malicious disk images. The issue occurs when a file is incorrectly marked as having both 'inline' data and 'extent' data, which are mutually exclusive storage methods. An attacker could exploit this by providing a corrupted filesystem to a user, leading to a denial of service or unauthorized system access.
Technical details
A vulnerability exists in the ext4 filesystem driver within the Linux kernel where it fails to detect an invalid combination of the INLINE_DATA and EXTENTS flags in an inode. When both flags are set, the `ext4_has_inline_data()` function returns true, which causes the kernel to skip essential extent tree validation in `__ext4_iget()`. Subsequent processing of unvalidated, out-of-order extents in `ext4_es_cache_extent()` leads to an integer underflow during hole size calculation, triggering a `BUG_ON` macro and resulting in a kernel panic. This can be triggered by mounting and accessing a maliciously corrupted ext4 filesystem. Patches have been released across various stable kernel branches to reject inodes with this invalid flag combination early in the `ext4_iget()` process.
Affected products
- Linux Linux Kernel 3.8 to 6.1.158
Timeline
- 2025-09-30: disclosed: Vulnerability reported by syzbot and fix proposed by developers.
- 2025-11-12: advisory: CVE-2025-40167 published.
References
- https://git.kernel.org/stable/c/1437c95ab2a28b138d4521653583729f61ccb48b
- https://git.kernel.org/stable/c/1d3ad183943b38eec2acf72a0ae98e635dc8456b
- https://git.kernel.org/stable/c/1f5ccd22ff482639133f2a0fe08f6d19d0e68717
- https://git.kernel.org/stable/c/2e9e10657b04152ed0d6ecae8d0c02a3405e28f5
- https://git.kernel.org/stable/c/4954d297c91d292630ab43ba4d195dc371ce65d3
- https://git.kernel.org/stable/c/cb6039b68efa547b676a8a10fc4618d9d1865c23
- https://git.kernel.org/stable/c/de985264eef64be8a90595908f2e6a87946dad34