CVE-2025-22079
Published: Apr 16, 2025
Modified: May 11, 2026
Description
In the Linux kernel, the following vulnerability has been resolved: ocfs2: validate l_tree_depth to avoid out-of-bounds access The l_tree_depth field is 16-bit (__le16), but the actual maximum depth is limited to OCFS2_MAX_PATH_DEPTH. Add a check to prevent out-of-bounds access if l_tree_depth has an invalid value, which may occur when reading from a corrupted mounted disk [1].
| Vendor | Product | Versions |
|---|---|---|
Linux | Linux | affected ccd979bdbce9fba8412beb3f1de68a9d0171b12c - < ef34840bda333fe99bafbd2d73b70ceaaf9eba66affected ccd979bdbce9fba8412beb3f1de68a9d0171b12c - < 538ed8b049ef801a86c543433e5061a91cc106e3affected ccd979bdbce9fba8412beb3f1de68a9d0171b12c - < 17c99ab3db2ba74096d36c69daa6e784e98fc0b8affected ccd979bdbce9fba8412beb3f1de68a9d0171b12c - < 11e24802e73362aa2948ee16b8fb4e32635d5b2aaffected ccd979bdbce9fba8412beb3f1de68a9d0171b12c - < 3d012ba4404a0bb517658699ba85e6abda386dc3+4 more versions |
Linux | Linux | affected 2.6.16unaffected 0 - < 2.6.16unaffected 5.4.292 - <= 5.4.*unaffected 5.10.236 - <= 5.10.*unaffected 5.15.180 - <= 5.15.*+6 more versions |
References
Security Training
Train your team to recognize and prevent security threats with our comprehensive security awareness program.
Start TrainingVulnerability Scanning
Discover vulnerabilities in your applications and infrastructure before attackers do.
Scan Now