CVE-2025-21699

CVSS 3.1 Score 5.5 of 10 (medium)

Details

Published Feb 12, 2025
Updated: Feb 14, 2025

Summary

CVE-2025-21699 is a vulnerability affecting the Linux kernel. It involves the gfs2 file system, where an issue was discovered with truncating an inode's address space. Specifically, when flipping the GFS2_DIF_JDATA flag, the address space is truncated in an inconsistent manner. Depending on the flag's state, pages in the address space utilize either buffer heads or iomap_folio_state structs. This vulnerability poses a risk as it can lead to unintended data handling and potential security implications if an attacker is able to manipulate the flag and exploit this inconsistency. The issue has been resolved in a recent kernel update.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share