Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

CVE-2025-40333— f2fs: fix infinite loop in __insert_extent_tree()

AI Predicted 5.5 Difficulty: Moderate EPSS 0.20% · P10

Possible ATT&CK Techniques 1AI

T1499 · Endpoint Denial of Service

Affected Version Matrix 10

VendorProductVersion RangeStatus
LinuxLinux98e4da8ca301e062d79ae168c67e56f3c3de3ce4< 765f8816d3959ef1f3f7f85e2af748594d091f40affected
98e4da8ca301e062d79ae168c67e56f3c3de3ce4< c0b9951bb2668d67eb4817bb23fc109abc08c075affected
98e4da8ca301e062d79ae168c67e56f3c3de3ce4< f4c31adcb2a0556f43776d4e51a67de88d7fb9eeaffected
98e4da8ca301e062d79ae168c67e56f3c3de3ce4< 23361bd54966b437e1ed3eb1a704572f4b279e58affected
3.8affected
< 3.8unaffected
6.6.117≤ 6.6.*unaffected
6.12.58≤ 6.12.*unaffected
… +2 more rows
Get alerts for future matching vulnerabilitiesLog in to subscribe

I. Basic Information for CVE-2025-40333

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
f2fs: fix infinite loop in __insert_extent_tree()
Source: CVE Program / CVE List V5
Vulnerability Description
In the Linux kernel, the following vulnerability has been resolved: f2fs: fix infinite loop in __insert_extent_tree() When we get wrong extent info data, and look up extent_node in rb tree, it will cause infinite loop (CONFIG_F2FS_CHECK_FS=n). Avoiding this by return NULL and print some kernel messages in that case.
Source: CVE Program / CVE List V5
CVSS Information
N/A
Source: CVE Program / CVE List V5
Vulnerability Type
N/A
Source: CVE Program / CVE List V5
Vulnerability Title
Linux kernel 安全漏洞
Source: CNNVD (China National Vulnerability Database)
Vulnerability Description
Linux kernel是美国Linux基金会的开源操作系统Linux所使用的内核。 Linux kernel存在安全漏洞,该漏洞源于错误数据导致无限循环。
Source: CNNVD (China National Vulnerability Database)
CVSS Information
N/A
Source: CNNVD (China National Vulnerability Database)
Vulnerability Type
N/A
Source: CNNVD (China National Vulnerability Database)

Affected Products

VendorProductAffected VersionsCPESubscribe
LinuxLinux 98e4da8ca301e062d79ae168c67e56f3c3de3ce4 ~ 765f8816d3959ef1f3f7f85e2af748594d091f40 -
LinuxLinux 3.8 -

II. Public POCs for CVE-2025-40333

#POC DescriptionSource LinkShenlong Link
AI-Generated POCPremium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2025-40333

登录查看更多情报信息。

Same Patch Batch · Linux · 2025-12-09 · 152 CVEs total

CVE-2025-403439.8 CRITICALnvmet-fc: avoid scheduling association deletion twice
CVE-2025-403428.8 HIGHnvme-fc: use lock accessing port_state and rport state
CVE-2025-403368.8 HIGHdrm/gpusvm: fix hmm_pfn_to_map_order() usage
CVE-2025-403288.8 HIGHsmb: client: fix potential UAF in smb2_close_cached_fid()
CVE-2025-403378.2 HIGHnet: stmmac: Correctly handle Rx checksum offload errors
CVE-2025-403447.8 HIGHASoC: Intel: avs: Disable periods-elapsed work when closing PCM
CVE-2025-403317.8 HIGHsctp: Prevent TOCTOU out-of-bounds write
CVE-2025-403347.3 HIGHdrm/amdgpu: validate userq buffer virtual address and size
CVE-2023-53825kcm: Fix error handling for SOCK_DGRAM in kcm_sendmsg().
CVE-2023-53841devlink: report devlink_port_type_warn source device
CVE-2023-53826ubi: Fix UAF wear-leveling entry in eraseblk_count_seq_show()
CVE-2023-53827Bluetooth: L2CAP: Fix use-after-free in l2cap_disconnect_{req,rsp}
CVE-2023-53828Bluetooth: hci_sync: Avoid use-after-free in dbg for hci_add_adv_monitor()
CVE-2023-53829f2fs: flush inode if atomic file is aborted
CVE-2023-53830platform/x86: think-lmi: Fix memory leak when showing current settings
CVE-2023-53831net: read sk->sk_family once in sk_mc_loop()
CVE-2023-53832md/raid10: fix null-ptr-deref in raid10_sync_request
CVE-2023-53840usb: early: xhci-dbc: Fix a potential out-of-bound memory access
CVE-2023-53839dccp: fix data-race around dp->dccps_mss_cache
CVE-2023-53838f2fs: synchronize atomic write aborts

Showing top 20 of 152 CVEs. View all on vendor page &rarr; →

IV. Related Vulnerabilities

V. Comments for CVE-2025-40333

No comments yet


Leave a comment