Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

CVE-2025-71107— f2fs: ensure node page reads complete before f2fs_put_super() finishes

Quick assessment

Affected
Linux Linux
Exploitation
No confirmed in-the-wild exploitation; assess based on exposure
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

Linux kernel是美国Linux基金会的开源操作系统Linux所使用的内核。 Linux kernel存在安全漏洞,该漏洞源于节点页读取未在f2fs_put_super完成前结束,可能导致文件系统引用计数泄漏。

AI Predicted 5.5 Difficulty: Moderate EPSS 0.17% · P6

Possible ATT&CK Techniques 1 AI

T1211 · Exploitation for Stealth

Affected Version Matrix 12

VendorProduct Version RangeStatus
Linux Linux 20872584b8c0b006c007da9588a272c9e28d2e18< c3031cf2b61f1508662fc95ef9ad505cb0882a5f affected
20872584b8c0b006c007da9588a272c9e28d2e18< 3b15d5f12935e9e25f9a571e680716bc9ee61025 affected
20872584b8c0b006c007da9588a272c9e28d2e18< 0b36fae23621a09e772c8adf918b9011158f8511 affected
20872584b8c0b006c007da9588a272c9e28d2e18< 297baa4aa263ff8f5b3d246ee16a660d76aa82c4 affected
0e2577074b459bba7f4016f4d725ede37d48bb22 affected
6.4.16< 6.5 affected
6.5 affected
< 6.5 unaffected
… +4 more rows
Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2025-71107

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
f2fs: ensure node page reads complete before f2fs_put_super() finishes
Source: CVE Program / CVE List V5
Vulnerability Description
In the Linux kernel, the following vulnerability has been resolved: f2fs: ensure node page reads complete before f2fs_put_super() finishes Xfstests generic/335, generic/336 sometimes crash with the following message: F2FS-fs (dm-0): detect filesystem reference count leak during umount, type: 9, count: 1 ------------[ cut here ]------------ kernel BUG at fs/f2fs/super.c:1939! Oops: invalid opcode: 0000 [#1] SMP NOPTI CPU: 1 UID: 0 PID: 609351 Comm: umount Tainted: G W 6.17.0-rc5-xfstests-g9dd1835ecda5 #1 PREEMPT(none) Tainted: [W]=WARN Hardware name: QEMU Standard PC (Q35 + ICH9, 2009), BIOS 1.16.3-debian-1.16.3-2 04/01/2014 RIP: 0010:f2fs_put_super+0x3b3/0x3c0 Call Trace: <TASK> generic_shutdown_super+0x7e/0x190 kill_block_super+0x1a/0x40 kill_f2fs_super+0x9d/0x190 deactivate_locked_super+0x30/0xb0 cleanup_mnt+0xba/0x150 task_work_run+0x5c/0xa0 exit_to_user_mode_loop+0xb7/0xc0 do_syscall_64+0x1ae/0x1c0 entry_SYSCALL_64_after_hwframe+0x76/0x7e </TASK> ---[ end trace 0000000000000000 ]--- It appears that sometimes it is possible that f2fs_put_super() is called before all node page reads are completed. Adding a call to f2fs_wait_on_all_pages() for F2FS_RD_NODE fixes the problem.
Source: CVE Program / CVE List V5
CVSS Information
N/A
Source: CVE Program / CVE List V5
Vulnerability Type
N/A
Source: CVE Program / CVE List V5
Vulnerability Title
Linux kernel 安全漏洞
Source: CNNVD (China National Vulnerability Database)
Vulnerability Description
Linux kernel是美国Linux基金会的开源操作系统Linux所使用的内核。 Linux kernel存在安全漏洞,该漏洞源于节点页读取未在f2fs_put_super完成前结束,可能导致文件系统引用计数泄漏。
Source: CNNVD (China National Vulnerability Database)
CVSS Information
N/A
Source: CNNVD (China National Vulnerability Database)
Vulnerability Type
N/A
Source: CNNVD (China National Vulnerability Database)

Affected Products

Vendor Product Affected Versions CPE Subscribe
Linux Linux 20872584b8c0b006c007da9588a272c9e28d2e18 ~ c3031cf2b61f1508662fc95ef9ad505cb0882a5f -
Linux Linux 6.5 -

II. Public POCs for CVE-2025-71107

# POC Description Source Link Shenlong Link
AI-Generated POC Premium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2025-71107

登录查看更多情报信息。

Same Patch Batch · Linux · 2026-01-14 · 43 CVEs total

CVE-2025-71116 9.1 CRITICAL libceph: make decode_pool() more resilient against corrupted osdmaps
CVE-2025-71112 8.8 HIGH net: hns3: add VLAN id validation before using
CVE-2025-71130 7.8 HIGH drm/i915/gem: Zero-initialize the eb.vma array in i915_gem_do_execbuffer
CVE-2025-71120 7.5 HIGH SUNRPC: svcauth_gss: avoid NULL deref on zero length gss_token in gss_read_proxy_verf
CVE-2025-71126 7.5 HIGH mptcp: avoid deadlock on fallback while reinjecting
CVE-2025-71128 7.5 HIGH erspan: Initialize options_len before referencing options.
CVE-2025-71131 7.5 HIGH crypto: seqiv - Do not use req->iv after crypto_aead_encrypt
CVE-2025-71132 7.5 HIGH smc91x: fix broken irq-context in PREEMPT_RT
CVE-2025-71127 7.1 HIGH wifi: mac80211: Discard Beacon frames to non-broadcast address
CVE-2025-71136 7.1 HIGH media: adv7842: Avoid possible out-of-bounds array accesses in adv7842_cp_log_status()
CVE-2025-71109 7.1 HIGH MIPS: ftrace: Fix memory corruption when kernel is located beyond 32 bits
CVE-2025-71108 usb: typec: ucsi: Handle incorrect num_connectors capability
CVE-2025-71111 hwmon: (w83791d) Convert macros to functions to avoid TOCTOU
CVE-2025-71104 KVM: x86: Fix VM hard lockup after prolonged inactivity with periodic HV timer
CVE-2025-71115 um: init cpu_tasks[] earlier
CVE-2025-71103 drm/msm: adreno: fix deferencing ifpc_reglist when not declared
CVE-2025-71117 block: Remove queue freezing from several sysfs store callbacks
CVE-2025-71118 ACPICA: Avoid walking the Namespace if start_node is NULL
CVE-2025-71102 scs: fix a wrong parameter in __scs_magic
CVE-2025-71105 f2fs: use global inline_xattr_slab instead of per-sb slab cache

Showing top 20 of 43 CVEs. View all on vendor page &rarr; →

IV. Related Vulnerabilities

V. Comments for CVE-2025-71107

Anonymous User
2026-01-15 06:08:19

Zaproxy alias impedit expedita quisquam pariatur exercitationem. Nemo rerum eveniet dolores rem quia dignissimos.


Leave a comment