SB2025090521 - Input validation error in Linux kernel ext4
Published: September 5, 2025
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 1 security vulnerability.
1) Input validation error (CVE-ID: CVE-2025-38701)
The vulnerability allows a local user to perform a denial of service (DoS) attack.
The vulnerability exists due to improper input validation within the ext4_create_inline_data(), ext4_update_inline_data() and ext4_inline_data_truncate() functions in fs/ext4/inline.c. A local user can perform a denial of service (DoS) attack.
Remediation
Install update from vendor's website.
References
- https://git.kernel.org/stable/c/099b847ccc6c1ad2f805d13cfbcc83f5b6d4bc42
- https://git.kernel.org/stable/c/1199a6399895f4767f0b9a68a6ff47c3f799b7c7
- https://git.kernel.org/stable/c/279c87ef7b9da34f65c2e4db586e730b667a6fb9
- https://git.kernel.org/stable/c/2817ac83cb4732597bf36853fe13ca616f4ee4e2
- https://git.kernel.org/stable/c/7f322c12df7aeed1755acd3c6fab48c7807795fb
- https://git.kernel.org/stable/c/8085a7324d8ec448c4a764af7853e19bbd64e17a
- https://git.kernel.org/stable/c/81e7e2e7ba07e7c8cdce43ccad2f91adbc5a919c
- https://git.kernel.org/stable/c/8a6f89d42e61788605722dd9faf98797c958a7e5
- https://git.kernel.org/stable/c/d960f4b793912f35e9d72bd9d1e90553063fcbf1