In the Linux kernel, the following vulnerability has been resolved:
f2fs: fix dereference of stale list iterator after loop body
The list iterator variable will be a bogus pointer if no break was hit. Dereferencing it (cur->page in this case) could load an out-of-bounds/undefined value making it unsafe to use that in the comparision to determine if the specific element was found.
Since 'cur->page' *can* be out-ouf-bounds it cannot be guaranteed that by chance (or intention of an attacker) it matches the value of 'page' even though the correct element was not found.
This is fixed by using a separate list iterator variable for the loop and only setting the original variable if a suitable element was found. Then determing if the element was found is simply checking if the variable is set.
CVSS Details
- CVSS 3.1 Base Score: 7.8
- CVSS 3.1 Vector: (CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Debian | — | Upgrade linux | Feb 27, 2025 | Feb 27, 2025 |
| Ubuntu | — | Upgrade linux-kvmUpgrade linux-lowlatencyUpgrade linux-gkeopUpgrade linux-azure-5.15Upgrade linux-azureUpgrade linux-gkeUpgrade linux-oracleUpgrade linux-oracle-5.4Upgrade linux-oracle-5.15Upgrade linux-raspiUpgrade linux-aws-5.4Upgrade linux-aws-hweUpgrade linux-intel-iotgUpgrade linux-fipsUpgrade linux-gcp-5.15Upgrade linux-ibm-5.4Upgrade linux-aws-fipsUpgrade linux-riscv-5.15Upgrade linuxUpgrade linux-ibmUpgrade linux-aws-5.15Upgrade linux-nvidiaUpgrade linux-azure-fipsUpgrade linux-hwe-5.15Upgrade linux-lowlatency-hwe-5.15Upgrade linux-hwe-5.4Upgrade linux-gcp-fipsUpgrade linux-realtimeUpgrade linux-azure-4.15Upgrade linux-gcpUpgrade linux-iotUpgrade linux-raspi-5.4Upgrade linux-gcp-5.4Upgrade linux-hweUpgrade linux-awsUpgrade linux-gcp-4.15Upgrade linux-azure-5.4Upgrade linux-bluefieldUpgrade linux-intel-iotg-5.15 | Mar 3, 2025 | Feb 26, 2025 |
| Vmware Photon_os | — | Use 'tdnf update' to upgrade all packages to the latest version. | May 27, 2026 | Feb 26, 2025 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub