Resource management error in Linux kernel - CVE-2025-40179
Published: November 13, 2025
Vulnerability identifier: #VU118499
CSH Severity: Low
CVSS v4.0: CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:U/U:Clear
CVE-ID: CVE-2025-40179
CWE-ID: CWE-399
Exploitation vector: Local access
Exploit availability:
No public exploit available
Vendor: Linux Foundation
Affected software:
Linux kernel
Linux kernel
Detailed vulnerability description
The vulnerability allows a local user to perform a denial of service (DoS) attack.
The vulnerability exists due to resource management error within the ext4_init_orphan_info() function in fs/ext4/orphan.c. A local user can perform a denial of service (DoS) attack.
How to mitigate CVE-2025-40179
Install update from vendor's repository.
Sources
- https://git.kernel.org/stable/c/0a6ce20c156442a4ce2a404747bb0fb05d54eeb3
- https://git.kernel.org/stable/c/2b9da798ff0f4d026c5f0f815047393ebe7d8859
- https://git.kernel.org/stable/c/304fc34ff6fc8261138fd81f119e024ac3a129e9
- https://git.kernel.org/stable/c/566a1d6084563bd07433025aa23bcea4427de107
- https://git.kernel.org/stable/c/95a21611b14ae0a401720645245a8db16f040995
- https://git.kernel.org/stable/c/a2d803fab8a6c6a874277cb80156dc114db91921