目标达成 感谢每一位支持者 — 我们达成了 100% 目标!

目标: 1000 元 · 已筹: 1336

100%

CVE-2025-37785— Linux kernel 安全漏洞

CVSS 7.8 · High EPSS 0.28% · P20

可能的 ATT&CK 技术 1AI

T1406.004

影响版本矩阵 20

厂商产品版本范围状态
LinuxLinuxac27a0ec112a089f1a5102bc8dffc79c8c815571< 14da7dbecb430e35b5889da8dae7bef33173b351affected
ac27a0ec112a089f1a5102bc8dffc79c8c815571< e47f472a664d70a3d104a6c2a035cdff55a719b4affected
ac27a0ec112a089f1a5102bc8dffc79c8c815571< b7531a4f99c3887439d778afaf418d1a01a5f01baffected
ac27a0ec112a089f1a5102bc8dffc79c8c815571< 89503e5eae64637d0fa2218912b54660effe7d93affected
ac27a0ec112a089f1a5102bc8dffc79c8c815571< 52a5509ab19a5d3afe301165d9b5787bba34d842affected
ac27a0ec112a089f1a5102bc8dffc79c8c815571< b47584c556444cf7acb66b26a62cbc348eb92b78affected
ac27a0ec112a089f1a5102bc8dffc79c8c815571< ac28c5684c1cdab650a7e5065b19e91577d37a4baffected
ac27a0ec112a089f1a5102bc8dffc79c8c815571< 53bc45da8d8da92ec07877f5922b130562eb4b00affected
… +12 条更多
获取后续新漏洞提醒登录后订阅

一、 漏洞 CVE-2025-37785 基础信息

漏洞信息

对漏洞内容有疑问?看看神龙的深度分析是否有帮助!
查看神龙十问 ↗

尽管我们使用了先进的大模型技术,但其输出仍可能包含不准确或过时的信息。神龙努力确保数据的准确性,但请您根据实际情况进行核实和判断。

Vulnerability Title
ext4: fix OOB read when checking dotdot dir
来源: CVE Program / CVE List V5
Vulnerability Description
In the Linux kernel, the following vulnerability has been resolved: ext4: fix OOB read when checking dotdot dir Mounting a corrupted filesystem with directory which contains '.' dir entry with rec_len == block size results in out-of-bounds read (later on, when the corrupted directory is removed). ext4_empty_dir() assumes every ext4 directory contains at least '.' and '..' as directory entries in the first data block. It first loads the '.' dir entry, performs sanity checks by calling ext4_check_dir_entry() and then uses its rec_len member to compute the location of '..' dir entry (in ext4_next_entry). It assumes the '..' dir entry fits into the same data block. If the rec_len of '.' is precisely one block (4KB), it slips through the sanity checks (it is considered the last directory entry in the data block) and leaves "struct ext4_dir_entry_2 *de" point exactly past the memory slot allocated to the data block. The following call to ext4_check_dir_entry() on new value of de then dereferences this pointer which results in out-of-bounds mem access. Fix this by extending __ext4_check_dir_entry() to check for '.' dir entries that reach the end of data block. Make sure to ignore the phony dir entries for checksum (by checking name_len for non-zero). Note: This is reported by KASAN as use-after-free in case another structure was recently freed from the slot past the bound, but it is really an OOB read. This issue was found by syzkaller tool. Call Trace: [ 38.594108] BUG: KASAN: slab-use-after-free in __ext4_check_dir_entry+0x67e/0x710 [ 38.594649] Read of size 2 at addr ffff88802b41a004 by task syz-executor/5375 [ 38.595158] [ 38.595288] CPU: 0 UID: 0 PID: 5375 Comm: syz-executor Not tainted 6.14.0-rc7 #1 [ 38.595298] Hardware name: QEMU Standard PC (i440FX + PIIX, 1996), BIOS rel-1.16.3-0-ga6ed6b701f0a-prebuilt.qemu.org 04/01/2014 [ 38.595304] Call Trace: [ 38.595308] <TASK> [ 38.595311] dump_stack_lvl+0xa7/0xd0 [ 38.595325] print_address_description.constprop.0+0x2c/0x3f0 [ 38.595339] ? __ext4_check_dir_entry+0x67e/0x710 [ 38.595349] print_report+0xaa/0x250 [ 38.595359] ? __ext4_check_dir_entry+0x67e/0x710 [ 38.595368] ? kasan_addr_to_slab+0x9/0x90 [ 38.595378] kasan_report+0xab/0xe0 [ 38.595389] ? __ext4_check_dir_entry+0x67e/0x710 [ 38.595400] __ext4_check_dir_entry+0x67e/0x710 [ 38.595410] ext4_empty_dir+0x465/0x990 [ 38.595421] ? __pfx_ext4_empty_dir+0x10/0x10 [ 38.595432] ext4_rmdir.part.0+0x29a/0xd10 [ 38.595441] ? __dquot_initialize+0x2a7/0xbf0 [ 38.595455] ? __pfx_ext4_rmdir.part.0+0x10/0x10 [ 38.595464] ? __pfx___dquot_initialize+0x10/0x10 [ 38.595478] ? down_write+0xdb/0x140 [ 38.595487] ? __pfx_down_write+0x10/0x10 [ 38.595497] ext4_rmdir+0xee/0x140 [ 38.595506] vfs_rmdir+0x209/0x670 [ 38.595517] ? lookup_one_qstr_excl+0x3b/0x190 [ 38.595529] do_rmdir+0x363/0x3c0 [ 38.595537] ? __pfx_do_rmdir+0x10/0x10 [ 38.595544] ? strncpy_from_user+0x1ff/0x2e0 [ 38.595561] __x64_sys_unlinkat+0xf0/0x130 [ 38.595570] do_syscall_64+0x5b/0x180 [ 38.595583] entry_SYSCALL_64_after_hwframe+0x76/0x7e
来源: CVE Program / CVE List V5
CVSS Information
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
来源: CVE Program / CVE List V5
Vulnerability Type
N/A
来源: CVE Program / CVE List V5
Vulnerability Title
Linux kernel 安全漏洞
来源: 中国国家信息安全漏洞库 CNNVD
Vulnerability Description
Linux kernel是美国Linux基金会的开源操作系统Linux所使用的内核。 Linux kernel存在安全漏洞,该漏洞源于ext4_empty_dir函数在检查dotdot目录时可能导致越界读取。
来源: 中国国家信息安全漏洞库 CNNVD
CVSS Information
N/A
来源: 中国国家信息安全漏洞库 CNNVD
Vulnerability Type
N/A
来源: 中国国家信息安全漏洞库 CNNVD

受影响产品

厂商产品影响版本CPE订阅
LinuxLinux ac27a0ec112a089f1a5102bc8dffc79c8c815571 ~ 14da7dbecb430e35b5889da8dae7bef33173b351 -
LinuxLinux 2.6.19 -

二、漏洞 CVE-2025-37785 的公开POC

#POC 描述源链接神龙链接
AI 生成 POC高级

未找到公开 POC。

登录以生成 AI POC

三、漏洞 CVE-2025-37785 的情报信息

登录查看更多情报信息。

CVE-2025-37785 补丁与修复 (1)

CVE-2025-37785 其他参考 (8)

同批安全公告 · Linux · 2025-04-18 · 共 23 条

CVE-2025-399308.4 HIGHLinux kernel 安全漏洞
CVE-2025-403647.8 HIGHLinux kernel 安全漏洞
CVE-2025-378387.8 HIGHLinux kernel 安全漏洞
CVE-2025-378937.8 HIGHLinux kernel 安全漏洞
CVE-2025-396887.5 HIGHLinux kernel 安全漏洞
CVE-2025-397357.1 HIGHLinux kernel 安全漏洞
CVE-2025-37860Linux kernel 安全漏洞
CVE-2025-37925Linux kernel 安全漏洞
CVE-2025-38049Linux kernel 安全漏洞
CVE-2025-38104Linux kernel 安全漏洞
CVE-2025-38152Linux kernel 安全漏洞
CVE-2025-38240Linux kernel 安全漏洞
CVE-2025-38479Linux kernel 安全漏洞
CVE-2025-38575Linux kernel 安全漏洞
CVE-2025-38637Linux kernel 安全漏洞
CVE-2025-39728Linux kernel 安全漏洞
CVE-2025-39755Linux kernel 安全漏洞
CVE-2025-39778Linux kernel 安全漏洞
CVE-2025-39989Linux kernel 安全漏洞
CVE-2025-40014Linux kernel 安全漏洞

显示前 20 条,共 23 条。 查看全部 &rarr; →

IV. Related Vulnerabilities

V. Comments for CVE-2025-37785

暂无评论


发表评论