目标达成 感谢每一位支持者 — 我们达成了 100% 目标!

目标: 1000 元 · 已筹: 1336

100%

CVE-2025-21722— Linux kernel 资源管理错误漏洞

CVSS 7.8 · High EPSS 0.20% · P10

可能的 ATT&CK 技术 1AI

T1499 · Endpoint Denial of Service

影响版本矩阵 16

厂商产品版本范围状态
LinuxLinux8c26c4e2694a163d525976e804d81cd955bbb40c< 7d0544bacc11d6aa26ecd7debf9353193c7a3328affected
8c26c4e2694a163d525976e804d81cd955bbb40c< 4d042811c72f71be7c14726db2c72b67025a7cb5affected
8c26c4e2694a163d525976e804d81cd955bbb40c< f51ff43c4c5a6c8e72d0aca89e4d5e688938412faffected
8c26c4e2694a163d525976e804d81cd955bbb40c< 19296737024cd220a1d6590bf4c092bca8c99497affected
8c26c4e2694a163d525976e804d81cd955bbb40c< 1098bb8d52419d262a3358d099a1598a920b730faffected
8c26c4e2694a163d525976e804d81cd955bbb40c< 557ccf5e49f1fb848a29698585bcab2e50a597efaffected
8c26c4e2694a163d525976e804d81cd955bbb40c< ca76bb226bf47ff04c782cacbd299f12ddee1ec1affected
3.10affected
… +8 条更多
获取后续新漏洞提醒登录后订阅

一、 漏洞 CVE-2025-21722 基础信息

漏洞信息

对漏洞内容有疑问?看看神龙的深度分析是否有帮助!
查看神龙十问 ↗

尽管我们使用了先进的大模型技术,但其输出仍可能包含不准确或过时的信息。神龙努力确保数据的准确性,但请您根据实际情况进行核实和判断。

Vulnerability Title
nilfs2: do not force clear folio if buffer is referenced
来源: CVE Program / CVE List V5
Vulnerability Description
In the Linux kernel, the following vulnerability has been resolved: nilfs2: do not force clear folio if buffer is referenced Patch series "nilfs2: protect busy buffer heads from being force-cleared". This series fixes the buffer head state inconsistency issues reported by syzbot that occurs when the filesystem is corrupted and falls back to read-only, and the associated buffer head use-after-free issue. This patch (of 2): Syzbot has reported that after nilfs2 detects filesystem corruption and falls back to read-only, inconsistencies in the buffer state may occur. One of the inconsistencies is that when nilfs2 calls mark_buffer_dirty() to set a data or metadata buffer as dirty, but it detects that the buffer is not in the uptodate state: WARNING: CPU: 0 PID: 6049 at fs/buffer.c:1177 mark_buffer_dirty+0x2e5/0x520 fs/buffer.c:1177 ... Call Trace: <TASK> nilfs_palloc_commit_alloc_entry+0x4b/0x160 fs/nilfs2/alloc.c:598 nilfs_ifile_create_inode+0x1dd/0x3a0 fs/nilfs2/ifile.c:73 nilfs_new_inode+0x254/0x830 fs/nilfs2/inode.c:344 nilfs_mkdir+0x10d/0x340 fs/nilfs2/namei.c:218 vfs_mkdir+0x2f9/0x4f0 fs/namei.c:4257 do_mkdirat+0x264/0x3a0 fs/namei.c:4280 __do_sys_mkdirat fs/namei.c:4295 [inline] __se_sys_mkdirat fs/namei.c:4293 [inline] __x64_sys_mkdirat+0x87/0xa0 fs/namei.c:4293 do_syscall_x64 arch/x86/entry/common.c:52 [inline] do_syscall_64+0xf3/0x230 arch/x86/entry/common.c:83 entry_SYSCALL_64_after_hwframe+0x77/0x7f The other is when nilfs_btree_propagate(), which propagates the dirty state to the ancestor nodes of a b-tree that point to a dirty buffer, detects that the origin buffer is not dirty, even though it should be: WARNING: CPU: 0 PID: 5245 at fs/nilfs2/btree.c:2089 nilfs_btree_propagate+0xc79/0xdf0 fs/nilfs2/btree.c:2089 ... Call Trace: <TASK> nilfs_bmap_propagate+0x75/0x120 fs/nilfs2/bmap.c:345 nilfs_collect_file_data+0x4d/0xd0 fs/nilfs2/segment.c:587 nilfs_segctor_apply_buffers+0x184/0x340 fs/nilfs2/segment.c:1006 nilfs_segctor_scan_file+0x28c/0xa50 fs/nilfs2/segment.c:1045 nilfs_segctor_collect_blocks fs/nilfs2/segment.c:1216 [inline] nilfs_segctor_collect fs/nilfs2/segment.c:1540 [inline] nilfs_segctor_do_construct+0x1c28/0x6b90 fs/nilfs2/segment.c:2115 nilfs_segctor_construct+0x181/0x6b0 fs/nilfs2/segment.c:2479 nilfs_segctor_thread_construct fs/nilfs2/segment.c:2587 [inline] nilfs_segctor_thread+0x69e/0xe80 fs/nilfs2/segment.c:2701 kthread+0x2f0/0x390 kernel/kthread.c:389 ret_from_fork+0x4b/0x80 arch/x86/kernel/process.c:147 ret_from_fork_asm+0x1a/0x30 arch/x86/entry/entry_64.S:244 </TASK> Both of these issues are caused by the callbacks that handle the page/folio write requests, forcibly clear various states, including the working state of the buffers they hold, at unexpected times when they detect read-only fallback. Fix these issues by checking if the buffer is referenced before clearing the page/folio state, and skipping the clear if it is.
来源: CVE Program / CVE List V5
CVSS Information
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
来源: CVE Program / CVE List V5
Vulnerability Type
N/A
来源: CVE Program / CVE List V5
Vulnerability Title
Linux kernel 资源管理错误漏洞
来源: 中国国家信息安全漏洞库 CNNVD
Vulnerability Description
Linux kernel是美国Linux基金会的开源操作系统Linux所使用的内核。 Linux kernel存在资源管理错误漏洞,该漏洞源于nilfs2强制清除被引用的缓冲区。
来源: 中国国家信息安全漏洞库 CNNVD
CVSS Information
N/A
来源: 中国国家信息安全漏洞库 CNNVD
Vulnerability Type
N/A
来源: 中国国家信息安全漏洞库 CNNVD

受影响产品

厂商产品影响版本CPE订阅
LinuxLinux 8c26c4e2694a163d525976e804d81cd955bbb40c ~ 7d0544bacc11d6aa26ecd7debf9353193c7a3328 -
LinuxLinux 3.10 -

二、漏洞 CVE-2025-21722 的公开POC

#POC 描述源链接神龙链接
AI 生成 POC高级

未找到公开 POC。

登录以生成 AI POC

三、漏洞 CVE-2025-21722 的情报信息

登录查看更多情报信息。

CVE-2025-21722 补丁与修复 (4)

CVE-2025-21722 其他参考 (3)

同批安全公告 · Linux · 2025-02-27 · 共 177 条

CVE-2025-218059.8 CRITICALLinux kernel 安全漏洞
CVE-2025-217079.8 CRITICALLinux kernel 安全漏洞
CVE-2025-217489.8 CRITICALLinux kernel 安全漏洞
CVE-2025-217969.8 CRITICALLinux kernel 资源管理错误漏洞
CVE-2024-580069.6 CRITICALLinux kernel 安全漏洞
CVE-2024-579978.8 HIGHLinux kernel 安全漏洞
CVE-2024-579958.8 HIGHLinux kernel 安全漏洞
CVE-2024-579998.8 HIGHLinux kernel 安全漏洞
CVE-2025-217358.8 HIGHLinux kernel 安全漏洞
CVE-2025-217108.2 HIGHLinux kernel 安全漏洞
CVE-2024-579738.1 HIGHLinux kernel 安全漏洞
CVE-2025-217608.1 HIGHLinux kernel 资源管理错误漏洞
CVE-2025-217628.1 HIGHLinux kernel 资源管理错误漏洞
CVE-2025-217668.1 HIGHLinux kernel 安全漏洞
CVE-2025-217658.1 HIGHLinux kernel 安全漏洞
CVE-2025-217187.8 HIGHLinux kernel 安全漏洞
CVE-2025-217307.8 HIGHLinux kernel 安全漏洞
CVE-2025-217297.8 HIGHLinux kernel 资源管理错误漏洞
CVE-2025-217537.8 HIGHLinux kernel 资源管理错误漏洞
CVE-2025-217177.8 HIGHLinux kernel 安全漏洞

显示前 20 条,共 177 条。 查看全部 &rarr; →

IV. Related Vulnerabilities

V. Comments for CVE-2025-21722

暂无评论


发表评论