Aller au contenu

Fiche vulnérabilité

CVE-2025-71292 : faille moyenne linux linux kernel (CVSS 5.5)

Description

In the Linux kernel, the following vulnerability has been resolved: jfs: nlink overflow in jfs_rename If nlink is maximal for a directory (-1) and inside that directory you perform a rename for some child directory (not moving from the parent), then the nlink of the first directory is first incremented and later decremented. Normally this is fine, but when nlink = -1 this causes a wrap around to 0, and then drop_nlink issues a warning. After applying the patch syzbot no longer issues any warnings. I also ran some basic fs tests to look for any regressions.

En bref

Sévérité
Moyenne (CVSS 5.5)
Vecteur CVSS
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
Exploitation active
Non signalée par la CISA
Publication
6 mai 2026
Dernière mise à jour
30 juil. 2026

Produits concernés

  • linux linux kernel

Références

Rechercher une autre vulnérabilité dans la base CVE