CVE-2025-0373

CVSS 3.1 Score 6 of 10 (medium)

Details

Published Jan 30, 2025
Updated: Feb 7, 2025
CWE ID 121

Summary

CVE-2025-0373 is a stack buffer overflow vulnerability affecting the implementation of VOP_VPTOFH() function in the cd9660, tarfs, and ext2fs file systems on 64-bit systems. An NFS server exporting one of these file systems can be made to panic when mounted and accessed by an NFS client, potentially leading to further exploitation, such as bypassing file permission checking or remote kernel code execution. However, demonstrating these advanced attacks has not been reported yet. Notably, release kernels with stack protection enabled can prevent some instances of the overflow, causing a panic instead.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share