Integer overflow in Linux kernel - CVE-2025-71292
Published: May 7, 2026
Linux kernel
Detailed vulnerability description
The vulnerability allows a local user to cause a denial of service.
The vulnerability exists due to an integer overflow in jfs_rename when renaming a child directory within the same parent directory while the parent directory link count is at its maximum value. A local user can rename a child directory in such a directory to cause a denial of service.
The issue can trigger a kernel warning when the directory link count wraps around to 0.
How to mitigate CVE-2025-71292
Sources
- https://git.kernel.org/stable/c/2108829a59f081e822fdab8c2cd7131deb8aa8a1
- https://git.kernel.org/stable/c/5d77c36cd4b698649f5c30c5f6c084f4f61d1880
- https://git.kernel.org/stable/c/9218dc26fd922b09858ecd3666ed57dfd8098da8
- https://git.kernel.org/stable/c/93c325746ae59709b4f9bad4e3e4761c8d566c70
- https://git.kernel.org/stable/c/a3d66089e50a6e0142f8884471f74292102ea9aa
- https://git.kernel.org/stable/c/b4330a0d0947fbdc9d445cbbeabd8cc910a8c9ca
- https://git.kernel.org/stable/c/f70fcbc2ac7c24f087a2c895c5753aa730b1e479
- https://git.kernel.org/stable/c/fe136426e30ca6debcf916fd6a141555ed9fde74