-

CVE-2025-40198

ext4: avoid potential buffer over-read in parse_apply_sb_mount_options()

In the Linux kernel, the following vulnerability has been resolved:

ext4: avoid potential buffer over-read in parse_apply_sb_mount_options()

Unlike other strings in the ext4 superblock, we rely on tune2fs to
make sure s_mount_opts is NUL terminated.  Harden
parse_apply_sb_mount_options() by treating s_mount_opts as a potential
__nonstring.
Daten sind bereitgestellt durch das CVE Programm von einer CVE Numbering Authority (CNA) (Unstrukturiert).
HerstellerLinux
Produkt Linux
Default Statusunaffected
Version 8b67f04ab9de5d8f3a71aef72bf02c995a506db5
Version < 7bf46ff83a0ef11836e38ebd72cdc5107209342d
Status affected
Version 8b67f04ab9de5d8f3a71aef72bf02c995a506db5
Version < b2bac84fde28fb6a88817b8b761abda17a1d300b
Status affected
Version 8b67f04ab9de5d8f3a71aef72bf02c995a506db5
Version < e651294218d2684302ee5ed95ccf381646f3e5b4
Status affected
Version 8b67f04ab9de5d8f3a71aef72bf02c995a506db5
Version < 01829af7656b56d83682b3491265d583d502e502
Status affected
Version 8b67f04ab9de5d8f3a71aef72bf02c995a506db5
Version < 2a0cf438320cdb783e0378570744c0ef0d83e934
Status affected
Version 8b67f04ab9de5d8f3a71aef72bf02c995a506db5
Version < a6e94557cd05adc82fae0400f6e17745563e5412
Status affected
Version 8b67f04ab9de5d8f3a71aef72bf02c995a506db5
Version < 8ecb790ea8c3fc69e77bace57f14cf0d7c177bd8
Status affected
HerstellerLinux
Produkt Linux
Default Statusaffected
Version 2.6.36
Status affected
Version 0
Version < 2.6.36
Status unaffected
Version <= 5.4.*
Version 5.4.301
Status unaffected
Version <= 5.10.*
Version 5.10.246
Status unaffected
Version <= 6.1.*
Version 6.1.158
Status unaffected
Version <= 6.6.*
Version 6.6.114
Status unaffected
Version <= 6.12.*
Version 6.12.54
Status unaffected
Version <= 6.17.*
Version 6.17.4
Status unaffected
Version <= *
Version 6.18
Status unaffected
VulnDex Vulnerability Enrichment
Diese Information steht angemeldeten Benutzern zur Verfügung. Login Login
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.06% 0.179
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
Es wurden noch keine Informationen zu CWE veröffentlicht.