SB20250620234 - Input validation error in Linux kernel orangefs
Published: June 20, 2025
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 1 security vulnerability.
1) Input validation error (CVE-ID: CVE-2025-38065)
The vulnerability allows a local user to perform a denial of service (DoS) attack.
The vulnerability exists due to improper input validation within the orangefs_writepage_locked() and orangefs_writepages_work() functions in fs/orangefs/inode.c. A local user can perform a denial of service (DoS) attack.
Remediation
Install update from vendor's website.
References
- https://git.kernel.org/stable/c/062e8093592fb866b8e016641a8b27feb6ac509d
- https://git.kernel.org/stable/c/121f0335d91e46369bf55b5da4167d82b099a166
- https://git.kernel.org/stable/c/15602508ad2f923e228b9521960b4addcd27d9c4
- https://git.kernel.org/stable/c/2323b806221e6268a4e17711bc72e2fc87c191a3
- https://git.kernel.org/stable/c/341e3a5984cf5761f3dab16029d7e9fb1641d5ff
- https://git.kernel.org/stable/c/5111227d7f1f57f6804666b3abf780a23f44fc1d
- https://git.kernel.org/stable/c/cd918ec24168fe08c6aafc077dd3b6d88364c5cf
- https://git.kernel.org/stable/c/ceaf195ed285b77791e29016ee6344b3ded609b3