PT-2025-8314 · Linux+1 · Linux Kernel+1
CVSS v3.1
5.5
Medium
| Vector | AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H |
Name of the Vulnerable Software and Affected Versions
Linux kernel versions prior to 5.17
Description
A flaw in the F2FS file system support within the Linux kernel can lead to a denial of service. The issue occurs in the
dec valid node count() function located in fs/f2fs/f2fs.h. The root cause is that the variables .total valid block count or .total valid node count can be fuzzed to zero; when dec valid node count() is subsequently called, it triggers a BUG ON() condition, resulting in a kernel panic.Recommendations
Update the Linux kernel to version 5.17 or later.
As a temporary mitigation, restrict the use of the
dec valid node count() function if possible.Exploit
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Astra Linux
Linux Kernel