GFS2 Inode Address Space Management Vulnerability in Linux Kernel
CVE-2025-21699

5.5MEDIUM

Key Information:

Vendor
Linux
Status
Vendor
CVE Published:
12 February 2025

Summary

A vulnerability exists in the Linux kernel related to the GFS2 file system's handling of inode address space when the GFS2_DIF_JDATA flag is toggled. This issue arises from the improper management of inode states, where the kernel may erroneously mix buffer heads with iomap_folio_state structures. Such a flaw could lead to inconsistencies in the inode's address space management, potentially causing data corruption or system instability.

Affected Version(s)

Linux 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 < 2b0bd5051ad1c1e9ef4879f18e15a7712c974f3e

Linux 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 < 8c41abc11aa8438c9ed2d973f97e66674c0355df

Linux 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 < 4e3ded34f3f3c9d7ed2aac7be8cf51153646574a

References

CVSS V3.1

Score:
5.5
Severity:
MEDIUM
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.