In the Linux kernel, the following vulnerability has been resolved:
f2fs: remove WARN_ON in f2fs_is_valid_blkaddr
Syzbot triggers two WARNs in f2fs_is_valid_blkaddr and __is_bitmap_valid. For example, in f2fs_is_valid_blkaddr, if type is DATA_GENERIC_ENHANCE or DATA_GENERIC_ENHANCE_READ, it invokes WARN_ON if blkaddr is not in the right range. The call trace is as follows:
f2fs_get_node_info+0x45f/0x1070 read_node_page+0x577/0x1190 __get_node_page.part.0+0x9e/0x10e0 __get_node_page f2fs_get_node_page+0x109/0x180 do_read_inode f2fs_iget+0x2a5/0x58b0 f2fs_fill_super+0x3b39/0x7ca0
Fix these two WARNs by replacing WARN_ON with dump_stack.
CVSS Details
- CVSS 3.1 Base Score: 5.5
- CVSS 3.1 Vector: (CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Debian | — | Upgrade linux | Feb 27, 2025 | Feb 27, 2025 |
| Ubuntu | — | Upgrade linux-azureUpgrade linux-awsUpgrade linux-iotUpgrade linux-aws-5.15Upgrade linux-oracle-5.4Upgrade linux-lowlatency-hwe-5.15Upgrade linux-intel-iotgUpgrade linux-intel-iotg-5.15Upgrade linux-fipsUpgrade linux-gcp-5.15Upgrade linux-aws-5.4Upgrade linux-riscv-5.15Upgrade linux-raspiUpgrade linux-kvmUpgrade linux-gkeUpgrade linux-bluefieldUpgrade linux-raspi-5.4Upgrade linux-hwe-5.15Upgrade linux-azure-5.4Upgrade linux-realtimeUpgrade linux-azure-fipsUpgrade linux-lowlatencyUpgrade linux-oracleUpgrade linux-azure-5.15Upgrade linux-gcpUpgrade linux-oracle-5.15Upgrade linux-aws-fipsUpgrade linux-ibm-5.4Upgrade linux-gkeopUpgrade linuxUpgrade linux-nvidiaUpgrade linux-ibmUpgrade linux-hwe-5.4Upgrade linux-gcp-fipsUpgrade linux-azure-fde-5.15Upgrade linux-gcp-5.4 | Mar 3, 2025 | Feb 26, 2025 |
| Vmware Photon_os | — | Use 'tdnf update' to upgrade all packages to the latest version. | May 27, 2026 | Feb 26, 2025 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub