CVE-2025-68251
Published: Dec 16, 2025
Modified: May 23, 2026
Description
In the Linux kernel, the following vulnerability has been resolved: erofs: avoid infinite loops due to corrupted subpage compact indexes Robert reported an infinite loop observed by two crafted images. The root cause is that `clusterofs` can be larger than `lclustersize` for !NONHEAD `lclusters` in corrupted subpage compact indexes, e.g.: blocksize = lclustersize = 512 lcn = 6 clusterofs = 515 Move the corresponding check for full compress indexes to `z_erofs_load_lcluster_from_disk()` to also cover subpage compact compress indexes. It also fixes the position of `m->type >= Z_EROFS_LCLUSTER_TYPE_MAX` check, since it should be placed right after `z_erofs_load_{compact,full}_lcluster()`.
| Vendor | Product | Versions |
|---|---|---|
Linux | Linux | affected 8d2517aaeea3ab8651bb517bca8f3c8664d318ea - < dbfac1b85d0753996ddfef636934d431b588dd1faffected 8d2517aaeea3ab8651bb517bca8f3c8664d318ea - < 8675447a8794983f2b7e694b378112772c17635eaffected 8d2517aaeea3ab8651bb517bca8f3c8664d318ea - < e13d315ae077bb7c3c6027cc292401bc0f4ec683affected 3f691aa676f29586e83e6c032713554a290418c3affected 22438a34d383ec2789eaf450728e38abc53051f8+2 more versions |
Linux | Linux | affected 6.8unaffected 0 - < 6.8unaffected 6.12.91 - <= 6.12.*unaffected 6.17.6 - <= 6.17.*unaffected 6.18 - <= * |
Security Training
Train your team to recognize and prevent security threats with our comprehensive security awareness program.
Start TrainingVulnerability Scanning
Discover vulnerabilities in your applications and infrastructure before attackers do.
Scan Now