CVE-2025-40205
Last modified
CVE-2025-40205 is a high-severity vulnerability rated 7.8/10 on the CVSS scale. In the Linux kernel, the following vulnerability has been resolved: btrfs: avoid potential out-of-bounds in btrfs_encode_fh() The function btrfs_encode_fh() does not properly account for the three cases it handles. Before writing to the file handle (fh), the function only returns to the user BTRFS_FID_SIZE_NON_CONNECTABLE (5 dwords, 20 bytes) or BTRFS_FID_SIZE_CONNECTABLE (8 dwords, 32 bytes). However, when a parent exists and the root ID of the parent and the inode are different, the function writes BTRFS_FID_SIZE_CONNECTABLE_ROOT (10 dwords, 40 bytes). If *max_len is not large enough, this write goes out of bounds because BTRFS_FID_SIZE_CONNECTABLE_ROOT is greater than BTRFS_FID_SIZE_CONNECTABLE originally returned. This results in an 8-byte out-of-bounds write at fid->parent_root_objectid = parent_root_id. A previous attempt to fix this issue was made but was lost. https://lore.kernel.org/all/4CADAEEC020000780001B32C@vpn.id2.novell.com/ Although this issue does not seem to be easily triggerable, it is a potential memory corruption bug that should be fixed. This patch resolves the issue by ensuring the function returns the appropriate size for all three cases and validates that *max_len is large enough before writing any data.. EPSS estimates a 0.19% chance of exploitation in the next 30 days.
Description
In the Linux kernel, the following vulnerability has been resolved: btrfs: avoid potential out-of-bounds in btrfs_encode_fh() The function btrfs_encode_fh() does not properly account for the three cases it handles. Before writing to the file handle (fh), the function only returns to the user BTRFS_FID_SIZE_NON_CONNECTABLE (5 dwords, 20 bytes) or BTRFS_FID_SIZE_CONNECTABLE (8 dwords, 32 bytes). However, when a parent exists and the root ID of the parent and the inode are different, the function writes BTRFS_FID_SIZE_CONNECTABLE_ROOT (10 dwords, 40 bytes). If *max_len is not large enough, this write goes out of bounds because BTRFS_FID_SIZE_CONNECTABLE_ROOT is greater than BTRFS_FID_SIZE_CONNECTABLE originally returned. This results in an 8-byte out-of-bounds write at fid->parent_root_objectid = parent_root_id. A previous attempt to fix this issue was made but was lost. https://lore.kernel.org/all/4CADAEEC020000780001B32C@vpn.id2.novell.com/ Although this issue does not seem to be easily triggerable, it is a potential memory corruption bug that should be fixed. This patch resolves the issue by ensuring the function returns the appropriate size for all three cases and validates that *max_len is large enough before writing any data.
Metrics
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Affected Software
Source: CNA advisory (CVE.org). NVD analysis pending.
| Vendor | Product | Versions |
|---|---|---|
| Linux | Linux | >= be6e8dc0ba84029997075a1ec77b4ddb863cbe15, < 60de2f55d2aca53e81b4ef2a67d7cc9e1eb677db; >= be6e8dc0ba84029997075a1ec77b4ddb863cbe15, < 742b44342204e5dfe3926433823623c1a0c581df; >= be6e8dc0ba84029997075a1ec77b4ddb863cbe15, < d3a9a8e1275eb9b87f006b5562a287aea3f6885f; >= be6e8dc0ba84029997075a1ec77b4ddb863cbe15, < d91f6626133698362bba08fbc04bd72c466806d3; >= be6e8dc0ba84029997075a1ec77b4ddb863cbe15, < 0276c8582488022f057b4cec21975a5edf079f47; >= be6e8dc0ba84029997075a1ec77b4ddb863cbe15, < 361d67276eb8ec6be8f27f4ad6c6090459438fee; >= be6e8dc0ba84029997075a1ec77b4ddb863cbe15, < 43143776b0a7604d873d1a6f3e552a00aa930224; >= be6e8dc0ba84029997075a1ec77b4ddb863cbe15, < dff4f9ff5d7f289e4545cc936362e01ed3252742 |
| Linux | Linux | 2.6.29 |
References
Timeline
- Published
- Last Modified
- Status
- Deferred
Frequently Asked Questions
What is CVE-2025-40205?
How severe is CVE-2025-40205?
How do I fix CVE-2025-40205?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2025
- CVE-2025-4020A vulnerability was found in PHPGurukul Old Age Home Managem…9.8
- CVE-2025-40200In the Linux kernel, the following vulnerability has been re…
- CVE-2025-40201In the Linux kernel, the following vulnerability has been re…7.8
- CVE-2025-40202In the Linux kernel, the following vulnerability has been re…7.8
- CVE-2025-40203In the Linux kernel, the following vulnerability has been re…7.8
- CVE-2025-40204In the Linux kernel, the following vulnerability has been re…8.1
- CVE-2025-40206In the Linux kernel, the following vulnerability has been re…7.8
- CVE-2025-40207In the Linux kernel, the following vulnerability has been re…
- CVE-2025-40208In the Linux kernel, the following vulnerability has been re…
- CVE-2025-40209In the Linux kernel, the following vulnerability has been re…
- CVE-2025-4021A vulnerability was found in code-projects Patient Record Ma…7.5
- CVE-2025-40210In the Linux kernel, the following vulnerability has been re…7.5
Are you affected by CVE-2025-40205?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
