In the Linux kernel, the following vulnerability has been resolved: ext4: ignore xattrs past end Once inside 'ext4_xattr_inode_dec_ref_all' we should ignore xattrs entries past the 'end' entry. Th…
High CVSS 7.8
Summary
In the Linux kernel, the following vulnerability has been resolved: ext4: ignore xattrs past end Once inside 'ext4_xattr_inode_dec_ref_all' we should ignore xattrs entries past the 'end' entry. This fixes the following KASAN reported issue: ================================================================== BUG: KASAN: slab-use-after-free in ext4_xattr_inode_dec_ref_all+0xb8c/0xe90 Read of size 4 at addr ffff888012c120c4 by task repro/2065 CPU: 1 UID: 0 PID: 2065 Comm: repro Not tainted 6.1…
In-depth triage · Auto channel
No in-depth report has been generated yet (DR-003 v2 AI pipeline is under construction).
Affected products
- :
- :
Sources
- NVD DATABASE
Original Links
- https://git.kernel.org/stable/c/362a90cecd36e8a5c415966d0b75b04a0270e4dd Patch
- https://git.kernel.org/stable/c/3bc6317033f365ce578eb6039445fb66162722fd Patch
- https://git.kernel.org/stable/c/6aff941cb0f7d0c897c3698ad2e30672709135e3 Patch
- https://git.kernel.org/stable/c/76c365fa7e2a8bb85f0190cdb4b8cdc99b2fdce3 Patch
- https://git.kernel.org/stable/c/836e625b03a666cf93ff5be328c8cb30336db872 Patch
- https://git.kernel.org/stable/c/c8e008b60492cf6fd31ef127aea6d02fd3d314cd Patch
- https://git.kernel.org/stable/c/cf9291a3449b04688b81e32621e88de8f4314b54 Patch
- https://git.kernel.org/stable/c/eb59cc31b6ea076021d14b04e7faab1636b87d0e Patch
- https://git.kernel.org/stable/c/f737418b6de31c962c7192777ee4018906975383 Patch
- https://lists.debian.org/debian-lts-announce/2025/05/msg00030.html Mailing List
- https://lists.debian.org/debian-lts-announce/2025/05/msg00045.html Mailing List
Timeline
- nvd_ingest NVD