目标达成 感谢每一位支持者 — 我们达成了 100% 目标!

目标: 1000 元 · 已筹: 1359 元

100%

CVE-2025-37785— Linux kernel 安全漏洞

一分钟漏洞结论

影响对象
Linux Linux
利用判断
尚无明确在野利用证据,仍需结合暴露面评估
建议动作
优先检查厂商安全公告和参考链接中的修复版本;无法立即升级时,限制受影响服务暴露并加强监测。

Linux kernel是美国Linux基金会的开源操作系统Linux所使用的内核。 Linux kernel存在安全漏洞,该漏洞源于ext4_empty_dir函数在检查dotdot目录时可能导致越界读取。

CVSS 7.8 · High EPSS 0.30% · P21

可能的 ATT&CK 技术 1 AI

T1406.004

影响版本矩阵 20

厂商产品 版本范围状态
Linux Linux ac27a0ec112a089f1a5102bc8dffc79c8c815571< 14da7dbecb430e35b5889da8dae7bef33173b351 affected
ac27a0ec112a089f1a5102bc8dffc79c8c815571< e47f472a664d70a3d104a6c2a035cdff55a719b4 affected
ac27a0ec112a089f1a5102bc8dffc79c8c815571< b7531a4f99c3887439d778afaf418d1a01a5f01b affected
ac27a0ec112a089f1a5102bc8dffc79c8c815571< 89503e5eae64637d0fa2218912b54660effe7d93 affected
ac27a0ec112a089f1a5102bc8dffc79c8c815571< 52a5509ab19a5d3afe301165d9b5787bba34d842 affected
ac27a0ec112a089f1a5102bc8dffc79c8c815571< b47584c556444cf7acb66b26a62cbc348eb92b78 affected
ac27a0ec112a089f1a5102bc8dffc79c8c815571< ac28c5684c1cdab650a7e5065b19e91577d37a4b affected
ac27a0ec112a089f1a5102bc8dffc79c8c815571< 53bc45da8d8da92ec07877f5922b130562eb4b00 affected
… +12 条更多
获取后续新漏洞提醒 登录后订阅

一、 漏洞 CVE-2025-37785 基础信息

漏洞信息

对漏洞内容有疑问?看看神龙的深度分析是否有帮助!
查看神龙十问 ↗

尽管我们使用了先进的大模型技术,但其输出仍可能包含不准确或过时的信息。神龙努力确保数据的准确性,但请您根据实际情况进行核实和判断。

Vulnerability Title
ext4: fix OOB read when checking dotdot dir
来源: CVE Program / CVE List V5
Vulnerability Description
In the Linux kernel, the following vulnerability has been resolved: ext4: fix OOB read when checking dotdot dir Mounting a corrupted filesystem with directory which contains '.' dir entry with rec_len == block size results in out-of-bounds read (later on, when the corrupted directory is removed). ext4_empty_dir() assumes every ext4 directory contains at least '.' and '..' as directory entries in the first data block. It first loads the '.' dir entry, performs sanity checks by calling ext4_check_dir_entry() and then uses its rec_len member to compute the location of '..' dir entry (in ext4_next_entry). It assumes the '..' dir entry fits into the same data block. If the rec_len of '.' is precisely one block (4KB), it slips through the sanity checks (it is considered the last directory entry in the data block) and leaves "struct ext4_dir_entry_2 *de" point exactly past the memory slot allocated to the data block. The following call to ext4_check_dir_entry() on new value of de then dereferences this pointer which results in out-of-bounds mem access. Fix this by extending __ext4_check_dir_entry() to check for '.' dir entries that reach the end of data block. Make sure to ignore the phony dir entries for checksum (by checking name_len for non-zero). Note: This is reported by KASAN as use-after-free in case another structure was recently freed from the slot past the bound, but it is really an OOB read. This issue was found by syzkaller tool. Call Trace: [ 38.594108] BUG: KASAN: slab-use-after-free in __ext4_check_dir_entry+0x67e/0x710 [ 38.594649] Read of size 2 at addr ffff88802b41a004 by task syz-executor/5375 [ 38.595158] [ 38.595288] CPU: 0 UID: 0 PID: 5375 Comm: syz-executor Not tainted 6.14.0-rc7 #1 [ 38.595298] Hardware name: QEMU Standard PC (i440FX + PIIX, 1996), BIOS rel-1.16.3-0-ga6ed6b701f0a-prebuilt.qemu.org 04/01/2014 [ 38.595304] Call Trace: [ 38.595308] <TASK> [ 38.595311] dump_stack_lvl+0xa7/0xd0 [ 38.595325] print_address_description.constprop.0+0x2c/0x3f0 [ 38.595339] ? __ext4_check_dir_entry+0x67e/0x710 [ 38.595349] print_report+0xaa/0x250 [ 38.595359] ? __ext4_check_dir_entry+0x67e/0x710 [ 38.595368] ? kasan_addr_to_slab+0x9/0x90 [ 38.595378] kasan_report+0xab/0xe0 [ 38.595389] ? __ext4_check_dir_entry+0x67e/0x710 [ 38.595400] __ext4_check_dir_entry+0x67e/0x710 [ 38.595410] ext4_empty_dir+0x465/0x990 [ 38.595421] ? __pfx_ext4_empty_dir+0x10/0x10 [ 38.595432] ext4_rmdir.part.0+0x29a/0xd10 [ 38.595441] ? __dquot_initialize+0x2a7/0xbf0 [ 38.595455] ? __pfx_ext4_rmdir.part.0+0x10/0x10 [ 38.595464] ? __pfx___dquot_initialize+0x10/0x10 [ 38.595478] ? down_write+0xdb/0x140 [ 38.595487] ? __pfx_down_write+0x10/0x10 [ 38.595497] ext4_rmdir+0xee/0x140 [ 38.595506] vfs_rmdir+0x209/0x670 [ 38.595517] ? lookup_one_qstr_excl+0x3b/0x190 [ 38.595529] do_rmdir+0x363/0x3c0 [ 38.595537] ? __pfx_do_rmdir+0x10/0x10 [ 38.595544] ? strncpy_from_user+0x1ff/0x2e0 [ 38.595561] __x64_sys_unlinkat+0xf0/0x130 [ 38.595570] do_syscall_64+0x5b/0x180 [ 38.595583] entry_SYSCALL_64_after_hwframe+0x76/0x7e
来源: CVE Program / CVE List V5
CVSS Information
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
来源: CVE Program / CVE List V5
Vulnerability Type
N/A
来源: CVE Program / CVE List V5
Vulnerability Title
Linux kernel 安全漏洞
来源: 中国国家信息安全漏洞库 CNNVD
Vulnerability Description
Linux kernel是美国Linux基金会的开源操作系统Linux所使用的内核。 Linux kernel存在安全漏洞,该漏洞源于ext4_empty_dir函数在检查dotdot目录时可能导致越界读取。
来源: 中国国家信息安全漏洞库 CNNVD
CVSS Information
N/A
来源: 中国国家信息安全漏洞库 CNNVD
Vulnerability Type
N/A
来源: 中国国家信息安全漏洞库 CNNVD

受影响产品

厂商 产品 影响版本 CPE 订阅
Linux Linux ac27a0ec112a089f1a5102bc8dffc79c8c815571 ~ 14da7dbecb430e35b5889da8dae7bef33173b351 -
Linux Linux 2.6.19 -

二、漏洞 CVE-2025-37785 的公开POC

# POC 描述 源链接 神龙链接
AI 生成 POC 高级

未找到公开 POC。

登录以生成 AI POC

三、漏洞 CVE-2025-37785 的情报信息

请登录查看更多情报信息。

CVE-2025-37785 补丁与修复 (1)

CVE-2025-37785 其他参考 (8)

同批安全公告 · Linux · 2025-04-18 · 共 23 条

CVE-2025-39930 8.4 HIGH Linux kernel 安全漏洞
CVE-2025-40364 7.8 HIGH Linux kernel 安全漏洞
CVE-2025-37838 7.8 HIGH Linux kernel 安全漏洞
CVE-2025-37893 7.8 HIGH Linux kernel 安全漏洞
CVE-2025-39688 7.5 HIGH Linux kernel 安全漏洞
CVE-2025-39735 7.1 HIGH Linux kernel 安全漏洞
CVE-2025-37860 Linux kernel 安全漏洞
CVE-2025-37925 Linux kernel 安全漏洞
CVE-2025-38049 Linux kernel 安全漏洞
CVE-2025-38104 Linux kernel 安全漏洞
CVE-2025-38152 Linux kernel 安全漏洞
CVE-2025-38240 Linux kernel 安全漏洞
CVE-2025-38479 Linux kernel 安全漏洞
CVE-2025-38575 Linux kernel 安全漏洞
CVE-2025-38637 Linux kernel 安全漏洞
CVE-2025-39728 Linux kernel 安全漏洞
CVE-2025-39755 Linux kernel 安全漏洞
CVE-2025-39778 Linux kernel 安全漏洞
CVE-2025-39989 Linux kernel 安全漏洞
CVE-2025-40014 Linux kernel 安全漏洞

显示前 20 条,共 23 条。 查看全部 &rarr; →

IV. Related Vulnerabilities

V. Comments for CVE-2025-37785

暂无评论


发表评论