Improper error handling in Linux kernel ext4



Risk Low
Patch available YES
Number of vulnerabilities 1
CVE-ID CVE-2025-38222
CWE-ID CWE-388
Exploitation vector Local
Public exploit N/A
Vulnerable software
Linux kernel
Operating systems & Components / Operating system

Vendor Linux Foundation

Security Bulletin

This security bulletin contains one low risk vulnerability.

1) Improper error handling

EUVDB-ID: #VU112319

Risk: Low

CVSSv4.0: 4.3 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:U/U:Clear]

CVE-ID: CVE-2025-38222

CWE-ID: CWE-388 - Error Handling

Exploit availability: No

Description

The vulnerability allows a local user to perform a denial of service (DoS) attack.

The vulnerability exists due to improper error handling within the ext4_prepare_inline_data() function in fs/ext4/inline.c. A local user can perform a denial of service (DoS) attack.

Mitigation

Install update from vendor's repository.

Vulnerable software versions

Linux kernel: All versions

CPE2.3 External links

https://git.kernel.org/stable/c/227cb4ca5a6502164f850d22aec3104d7888b270
https://git.kernel.org/stable/c/26e09d18599da0adc543eabd300080daaeda6869
https://git.kernel.org/stable/c/5766da2237e539f259aa0e5f3639ae37b44ca458
https://git.kernel.org/stable/c/717414a8c083c376d4a8940a1230fe0c6ed4ee00
https://git.kernel.org/stable/c/9d1d1c5bf4fc1af76be154d3afb2acdbd89ec7d8
https://git.kernel.org/stable/c/cf5f319a2d8ab8238f8cf3a19463b9bff6420934
https://git.kernel.org/stable/c/d3dfc60efd145df5324b99a244b0b05505cde29b
https://git.kernel.org/stable/c/e80ee0263d88d77f2fd1927f915003a7066cbb50


Q & A

Can this vulnerability be exploited remotely?

No. This vulnerability can be exploited locally. The attacker should have authentication credentials and successfully authenticate on the system.

Is there known malware, which exploits this vulnerability?

No. We are not aware of malware exploiting this vulnerability.



###SIDEBAR###