In the Linux kernel, the following vulnerability has been resolved:
ext4: fix BUG_ON() when directory entry has invalid rec_len
The rec_len field in the directory entry has to be a multiple of 4. A corrupted filesystem image can be used to hit a BUG() in ext4_rec_len_to_disk(), called from make_indexed_dir().
------------[ cut here ]------------ kernel BUG at fs/ext4/ext4.h:2413! ... RIP: 0010:make_indexed_dir+0x53f/0x5f0 ... Call Trace: <TASK> ? add_dirent_to_buf+0x1b2/0x200 ext4_add_entry+0x36e/0x480 ext4_add_nondir+0x2b/0xc0 ext4_create+0x163/0x200 path_openat+0x635/0xe90 do_filp_open+0xb4/0x160 ? __create_object.isra.0+0x1de/0x3b0 ? _raw_spin_unlock+0x12/0x30 do_sys_openat2+0x91/0x150 __x64_sys_open+0x6c/0xa0 do_syscall_64+0x3c/0x80 entry_SYSCALL_64_after_hwframe+0x46/0xb0
The fix simply adds a call to ext4_check_dir_entry() to validate the directory entry, returning -EFSCORRUPTED if the entry is invalid.
CVSS Details
- CVSS 3.1 Base Score: 5.5
- CVSS 3.1 Vector: (CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Amazon Linux Ami 2 | — | Upgrade kernelUpgrade perf-debuginfoUpgrade python-perf-debuginfoUpgrade kernel-headersUpgrade kernel-tools-develUpgrade kernel-livepatch-5.10.155-138.670Upgrade perfUpgrade kernel-toolsUpgrade kernel-debuginfo-common-aarch64Upgrade kernel-livepatch-5.15.79-51.138Upgrade kernel-debuginfo-common-x86_64Upgrade kernel-tools-debuginfoUpgrade bpftoolUpgrade kernel-debuginfoUpgrade bpftool-debuginfoUpgrade python-perfUpgrade kernel-devel | Jun 23, 2025 | May 1, 2025 |
| Debian | — | Upgrade linux | May 5, 2025 | May 1, 2025 |
| Huawei Euleros 2_0_sp13 | — | Upgrade kernelUpgrade kernel-abi-stablelistsUpgrade kernel-toolsUpgrade kernel-tools-libsUpgrade python3-perfUpgrade bpftool | Aug 13, 2025 | Aug 9, 2025 |
| Redhat_linux | — | No solution exists | Jul 9, 2025 | May 1, 2025 |
| Ubuntu | — | Upgrade linux-lowlatency-hwe-5.15Upgrade linux-gcp-5.15Upgrade linux-intel-iotg-5.15Upgrade linux-hwe-5.15Upgrade linux-bluefieldUpgrade linux-raspi-5.4Upgrade linux-oracle-5.15Upgrade linux-awsUpgrade linux-realtimeUpgrade linux-gkeUpgrade linux-oracle-5.4Upgrade linux-azureUpgrade linux-kvmUpgrade linux-lowlatencyUpgrade linux-iotUpgrade linux-aws-5.4Upgrade linux-raspiUpgrade linux-aws-5.15Upgrade linux-hwe-5.4Upgrade linux-oracleUpgrade linux-azure-fde-5.15Upgrade linux-gcp-5.4Upgrade linux-fipsUpgrade linux-azure-5.15Upgrade linux-riscv-5.15Upgrade linux-gcp-fipsUpgrade linux-ibm-5.4Upgrade linux-aws-fipsUpgrade linux-intel-iotgUpgrade linux-gcpUpgrade linux-azure-5.4Upgrade linuxUpgrade linux-nvidiaUpgrade linux-ibmUpgrade linux-azure-fipsUpgrade linux-gkeopUpgrade linux-xilinx-zynqmp | May 6, 2025 | May 1, 2025 |
| Vmware Photon_os | — | Use 'tdnf update' to upgrade all packages to the latest version. | May 27, 2026 | May 1, 2025 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub