ext4: detect invalid INLINE_DATA + EXTENTS flag combination
Summary
| CVE | CVE-2025-40167 |
|---|---|
| State | PUBLISHED |
| Assigner | Linux |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2025-11-12 11:15:47 UTC |
| Updated | 2026-07-30 06:24:14 UTC |
| Description | In the Linux kernel, the following vulnerability has been resolved: ext4: detect invalid INLINE_DATA + EXTENTS flag combination syzbot reported a BUG_ON in ext4_es_cache_extent() when opening a verity file on a corrupted ext4 filesystem mounted without a journal. The issue is that the filesystem has an inode with both the INLINE_DATA and EXTENTS flags set: EXT4-fs error (device loop0): ext4_cache_extents:545: inode #15: comm syz.0.17: corrupted extent tree: lblk 0 < prev 66 Investigation revealed that the inode has both flags set: DEBUG: inode 15 - flag=1, i_inline_off=164, has_inline=1, extents_flag=1 This is an invalid combination since an inode should have either: - INLINE_DATA: data stored directly in the inode - EXTENTS: data stored in extent-mapped blocks Having both flags causes ext4_has_inline_data() to return true, skipping extent tree validation in __ext4_iget(). The unvalidated out-of-order extents then trigger a BUG_ON in ext4_es_cache_extent() due to integer underflow when calculating hole sizes. Fix this by detecting this invalid flag combination early in ext4_iget() and rejecting the corrupted inode. |
Risk And Classification
Primary CVSS: v3.1 7.8 HIGH from 416baaa9-dc9f-4396-8d5f-8c081fb06d67
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
EPSS: 0.001500000 probability, percentile 0.046870000 (date 2026-07-31)
| Version | Source | Type | Score | Severity | Vector |
|---|---|---|---|---|---|
| 3.1 | 416baaa9-dc9f-4396-8d5f-8c081fb06d67 | Secondary | 7.8 | HIGH | CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H |
| 3.1 | CNA | DECLARED | 7.8 | HIGH | CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H |
CVSS v3.1 Breakdown
Attack Vector
LocalAttack Complexity
LowPrivileges Required
NoneUser Interaction
RequiredScope
UnchangedConfidentiality
HighIntegrity
HighAvailability
HighCVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Vendor Declared Affected Products
| Source | Vendor | Product | Version | Platforms |
|---|---|---|---|---|
| CNA | Linux | Linux | affected f19d5870cbf72d4cb2a8e1f749dff97af99b071e 4954d297c91d292630ab43ba4d195dc371ce65d3 git | Not specified |
| CNA | Linux | Linux | affected f19d5870cbf72d4cb2a8e1f749dff97af99b071e f061f7c331fc16250fc82aa68964f35821687217 git | Not specified |
| CNA | Linux | Linux | affected f19d5870cbf72d4cb2a8e1f749dff97af99b071e 2e9e10657b04152ed0d6ecae8d0c02a3405e28f5 git | Not specified |
| CNA | Linux | Linux | affected f19d5870cbf72d4cb2a8e1f749dff97af99b071e 1437c95ab2a28b138d4521653583729f61ccb48b git | Not specified |
| CNA | Linux | Linux | affected f19d5870cbf72d4cb2a8e1f749dff97af99b071e cb6039b68efa547b676a8a10fc4618d9d1865c23 git | Not specified |
| CNA | Linux | Linux | affected f19d5870cbf72d4cb2a8e1f749dff97af99b071e de985264eef64be8a90595908f2e6a87946dad34 git | Not specified |
| CNA | Linux | Linux | affected f19d5870cbf72d4cb2a8e1f749dff97af99b071e 1f5ccd22ff482639133f2a0fe08f6d19d0e68717 git | Not specified |
| CNA | Linux | Linux | affected f19d5870cbf72d4cb2a8e1f749dff97af99b071e 1d3ad183943b38eec2acf72a0ae98e635dc8456b git | Not specified |
| CNA | Linux | Linux | affected 3.8 | Not specified |
| CNA | Linux | Linux | unaffected 3.8 semver | Not specified |
| CNA | Linux | Linux | unaffected 5.4.301 5.4.* semver | Not specified |
| CNA | Linux | Linux | unaffected 5.10.246 5.10.* semver | Not specified |
| CNA | Linux | Linux | unaffected 5.15.196 5.15.* semver | Not specified |
| CNA | Linux | Linux | unaffected 6.1.158 6.1.* semver | Not specified |
| CNA | Linux | Linux | unaffected 6.6.114 6.6.* semver | Not specified |
| CNA | Linux | Linux | unaffected 6.12.55 6.12.* semver | Not specified |
| CNA | Linux | Linux | unaffected 6.17.5 6.17.* semver | Not specified |
| CNA | Linux | Linux | unaffected 6.18 * original_commit_for_fix | Not specified |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| git.kernel.org/stable/c/1f5ccd22ff482639133f2a0fe08f6d19d0e68717 | 416baaa9-dc9f-4396-8d5f-8c081fb06d67 | git.kernel.org | |
| git.kernel.org/stable/c/1d3ad183943b38eec2acf72a0ae98e635dc8456b | 416baaa9-dc9f-4396-8d5f-8c081fb06d67 | git.kernel.org | |
| git.kernel.org/stable/c/1437c95ab2a28b138d4521653583729f61ccb48b | 416baaa9-dc9f-4396-8d5f-8c081fb06d67 | git.kernel.org | |
| git.kernel.org/stable/c/cb6039b68efa547b676a8a10fc4618d9d1865c23 | 416baaa9-dc9f-4396-8d5f-8c081fb06d67 | git.kernel.org | |
| git.kernel.org/stable/c/f061f7c331fc16250fc82aa68964f35821687217 | 416baaa9-dc9f-4396-8d5f-8c081fb06d67 | git.kernel.org | |
| git.kernel.org/stable/c/2e9e10657b04152ed0d6ecae8d0c02a3405e28f5 | 416baaa9-dc9f-4396-8d5f-8c081fb06d67 | git.kernel.org | |
| git.kernel.org/stable/c/de985264eef64be8a90595908f2e6a87946dad34 | 416baaa9-dc9f-4396-8d5f-8c081fb06d67 | git.kernel.org | |
| git.kernel.org/stable/c/4954d297c91d292630ab43ba4d195dc371ce65d3 | 416baaa9-dc9f-4396-8d5f-8c081fb06d67 | git.kernel.org | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.