Review reviewHigh

CVE-2025-40190

Linux

In the Linux kernel, the following vulnerability has been resolved: ext4: guard against EA inode refcount underflow in xattr update syzkaller found a path where ext4_xattr_inode_update_ref() reads an EA inode refcount that is already <= 0 and then applies ref_change (often -1). That lets the refcount underflow and we proceed with a bogus value, triggering errors like: EXT4-fs error: EA inode <n> ref underflow: ref_count=-1 ref_change=-1 EXT4-fs warning: ea_inode dec ref err=-117 Make the invariant explicit: if the current refcount is non-positive, treat this as on-disk corruption, emit ext4...

CVSS
7.8
EPSS
0.16%
5.70% percentile
CISA KEV
Not listed
Published
2025.11.13
PRIORITY ASSESSMENT

Review review

The CVSS severity warrants an early asset and exposure review.

Known exploitationNot established by KEV
Exploit probability0.16%
Technical severityCVSS 7.8

Vulnerability overview

In the Linux kernel, the following vulnerability has been resolved: ext4: guard against EA inode refcount underflow in xattr update syzkaller found a path where ext4_xattr_inode_update_ref() reads an EA inode refcount that is already <= 0 and then applies ref_change (often -1). That lets the refcount underflow and we proceed with a bogus value, triggering errors like: EXT4-fs error: EA inode <n> ref underflow: ref_count=-1 ref_change=-1 EXT4-fs warning: ea_inode dec ref err=-117 Make the invariant explicit: if the current refcount is non-positive, treat this as on-disk corruption, emit ext4...

Affected product and versions

Product
Linux
Affected versions
>= 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 < ea39e712c2f5ae148ee5515798ae03523673e002, >= 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 < 1cfb3e4ddbdc8e02e637b8852540bd4718bf4814, >= 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 < 505e69f76ac497e788f4ea0267826ec7266b40c8, >= 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 < 3d6269028246f4484bfed403c947a114bb583631, >= 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 < 79ea7f3e11effe1bd9e753172981d9029133a278, >= 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 < 6b879c4c6bbaab03c0ad2a983953bd1410bb165e, >= 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 < 440b003f449a4ff2a00b08c8eab9ba5cd28f3943, >= 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 < 57295e835408d8d425bef58da5253465db3d6888, < 5.4.301, < 5.10.246, < 5.15.195, < 6.1.157, < 6.6.113, < 6.12.54, < 6.17.4
Fixed versions
No verified fixed-version field is available yet

Recommended response sequence

Confirm exposure before applying a vendor-supported change.

Full remediation guide
  1. 1
    Identify

    Confirm that Linux and an affected version are present.

  2. 2
    Prioritize

    Combine exploitation signals with asset exposure and business criticality.

  3. 3
    Remediate

    Follow the vendor advisory or supported update path and preserve rollback options.

  4. 4
    Verify

    Recheck the version, service health, access paths, and relevant logs.

Technical data

CVSS vector
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
CWE
Not available
CVE-2025-40190 — Linux | SECUFOCUS NOW