Junglewise Threat Intelligence

CVE-2025-40167: Linux Kernel ext4 denial of service via invalid inode flags

CVE-2025-40167 · Severity: high · CVSS 7.8 · Published 2025-11-12

Technologies: Linux Kernel. Vendors: Linux.

Executive brief

A vulnerability in the Linux kernel's ext4 file system could allow a system crash or potential data corruption when handling specially crafted, malicious disk images. The issue occurs when a file is incorrectly marked as having both 'inline' data and 'extent' data, which are mutually exclusive storage methods. An attacker could exploit this by providing a corrupted filesystem to a user, leading to a denial of service or unauthorized system access.

Technical details

A vulnerability exists in the ext4 filesystem driver within the Linux kernel where it fails to detect an invalid combination of the INLINE_DATA and EXTENTS flags in an inode. When both flags are set, the `ext4_has_inline_data()` function returns true, which causes the kernel to skip essential extent tree validation in `__ext4_iget()`. Subsequent processing of unvalidated, out-of-order extents in `ext4_es_cache_extent()` leads to an integer underflow during hole size calculation, triggering a `BUG_ON` macro and resulting in a kernel panic. This can be triggered by mounting and accessing a maliciously corrupted ext4 filesystem. Patches have been released across various stable kernel branches to reject inodes with this invalid flag combination early in the `ext4_iget()` process.

Affected products

  • Linux Linux Kernel 3.8 to 6.1.158

Timeline

  • 2025-09-30: disclosed: Vulnerability reported by syzbot and fix proposed by developers.
  • 2025-11-12: advisory: CVE-2025-40167 published.

References

Related threats