Review reviewHigh

CVE-2025-40167

Linux

In the Linux kernel, the following vulnerability has been resolved: ext4: detect invalid INLINE_DATA + EXTENTS flag combination syzbot reported a BUG_ON in ext4_es_cache_extent() when opening a verity file on a corrupted ext4 filesystem mounted without a journal. The issue is that the filesystem has an inode with both the INLINE_DATA and EXTENTS flags set: EXT4-fs error (device loop0): ext4_cache_extents:545: inode #15: comm syz.0.17: corrupted extent tree: lblk 0 < prev 66 Investigation revealed that the inode has both flags set: DEBUG: inode 15 - flag=1, i_inline_off=164, has_inline=1, ex...

CVSS
7.8
EPSS
0.15%
4.65% percentile
CISA KEV
Not listed
Published
2025.11.12
PRIORITY ASSESSMENT

Review review

The CVSS severity warrants an early asset and exposure review.

Known exploitationNot established by KEV
Exploit probability0.15%
Technical severityCVSS 7.8

Vulnerability overview

In the Linux kernel, the following vulnerability has been resolved: ext4: detect invalid INLINE_DATA + EXTENTS flag combination syzbot reported a BUG_ON in ext4_es_cache_extent() when opening a verity file on a corrupted ext4 filesystem mounted without a journal. The issue is that the filesystem has an inode with both the INLINE_DATA and EXTENTS flags set: EXT4-fs error (device loop0): ext4_cache_extents:545: inode #15: comm syz.0.17: corrupted extent tree: lblk 0 < prev 66 Investigation revealed that the inode has both flags set: DEBUG: inode 15 - flag=1, i_inline_off=164, has_inline=1, ex...

Affected product and versions

Product
Linux
Affected versions
>= f19d5870cbf72d4cb2a8e1f749dff97af99b071e < 4954d297c91d292630ab43ba4d195dc371ce65d3, >= f19d5870cbf72d4cb2a8e1f749dff97af99b071e < f061f7c331fc16250fc82aa68964f35821687217, >= f19d5870cbf72d4cb2a8e1f749dff97af99b071e < 2e9e10657b04152ed0d6ecae8d0c02a3405e28f5, >= f19d5870cbf72d4cb2a8e1f749dff97af99b071e < 1437c95ab2a28b138d4521653583729f61ccb48b, >= f19d5870cbf72d4cb2a8e1f749dff97af99b071e < cb6039b68efa547b676a8a10fc4618d9d1865c23, >= f19d5870cbf72d4cb2a8e1f749dff97af99b071e < de985264eef64be8a90595908f2e6a87946dad34, >= f19d5870cbf72d4cb2a8e1f749dff97af99b071e < 1f5ccd22ff482639133f2a0fe08f6d19d0e68717, >= f19d5870cbf72d4cb2a8e1f749dff97af99b071e < 1d3ad183943b38eec2acf72a0ae98e635dc8456b, >= 3.8
Fixed versions
No verified fixed-version field is available yet

Recommended response sequence

Confirm exposure before applying a vendor-supported change.

Full remediation guide
  1. 1
    Identify

    Confirm that Linux and an affected version are present.

  2. 2
    Prioritize

    Combine exploitation signals with asset exposure and business criticality.

  3. 3
    Remediate

    Follow the vendor advisory or supported update path and preserve rollback options.

  4. 4
    Verify

    Recheck the version, service health, access paths, and relevant logs.

Technical data

CVSS vector
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
CWE
Not available
CVE-2025-40167 — Linux | SECUFOCUS NOW