CVE-2025-23150

Kernel memory corruption via ext4 split miscalculation

Published May 1, 2025 · Updated Aug 5, 2026

Use-after-free in the Linux kernel ext4 directory code allows local users to corrupt kernel memory through crafted file names. The do_split loop can decrement its index to -1 while dividing a directory block, causing ext4_insert_dentry to write beyond the selected entries. Reachability requires local filesystem operations that fill one ext4 directory with many long names; the resulting memory corruption can crash the kernel.

CVSS severity7.8
High
EPSS probability0.22%
Next 30 days · Sep 16, 2026
Known exploitationUnconfirmed
Based on sourced intelligence
Hinoki checkNot available
Coverage for this vulnerability

See if you're affected

Explore vulnerability checks for your environment with Hinoki.

Book a demo

Summary

What happened

Use-after-free in the Linux kernel ext4 directory code allows local users to corrupt kernel memory through crafted file names. The do_split loop can decrement its index to -1 while dividing a directory block, causing ext4_insert_dentry to write beyond the selected entries. Reachability requires local filesystem operations that fill one ext4 directory with many long names; the resulting memory corruption can crash the kernel.

The record

CVE
CVE-2025-23150
Published
May 1, 2025
Updated
Aug 5, 2026
Vendor
The Linux Kernel Organization
Product
Linux
Classifications
CWE-193
Attack vector
local
Privileges
authenticated

Timeline

How it unfolded

  1. May 1, 2025CVE publishedPublication date reported by the CVE source.
  2. Aug 5, 2026Record updatedLatest update available in the CVE record.

Exploitability

Present is not the same as exploitable

Compare your product and version with the public record. A matching version still requires validation against your environment.

Is a vulnerable build present?

Compare these published version ranges with your installed build and any vendor patches.

  1. Affected versionversion=059b1480105478c5f68cf664301545b8cad6a7cf
  2. Affected versionversion=4.14.195 <4.15
  3. Affected versionversion=4.19.142 <4.20
  4. Affected versionversion=4.4.234 <4.5
  5. Affected versionversion=4.9.234 <4.10
  6. Affected versionversion=539ae3e03875dacaa9c388aff141ccbb4ef4ecb5
  7. Affected versionversion=5.4.61 <5.4.293
  8. Affected versionversion=5.7.18 <5.8
  9. Affected versionversion=5.8.4 <5.9
  10. Affected versionversion=5872331b3d91820e14716632ebb56b1399b34fe1 <16d9067f00e3a7d1df7c3aa9c20d214923d27e10
  11. Affected versionversion=5872331b3d91820e14716632ebb56b1399b34fe1 <17df39f455f1289319d4d09e4826aa46852ffd17
  12. Affected versionversion=5872331b3d91820e14716632ebb56b1399b34fe1 <2883e9e74f73f9265e5f8d1aaaa89034b308e433
  13. Affected versionversion=5872331b3d91820e14716632ebb56b1399b34fe1 <2eeb1085bf7bd5c7ba796ca4119925fa5d336a3f
  14. Affected versionversion=5872331b3d91820e14716632ebb56b1399b34fe1 <35d0aa6db9d93307085871ceab8a729594a98162
  15. Affected versionversion=5872331b3d91820e14716632ebb56b1399b34fe1 <515c34cff899eb5dae6aa7eee01c1295b07d81af
  16. Affected versionversion=5872331b3d91820e14716632ebb56b1399b34fe1 <94824ac9a8aaf2fb3c54b4bdde842db80ffa555d
  17. Affected versionversion=5872331b3d91820e14716632ebb56b1399b34fe1 <ab0cc5c25552ae0d20eae94b40a93be11b080fc5
  18. Affected versionversion=5.9
  19. Affected versionversion=88e79f7a9841278fa8ff7ff6178bad12da002ffc
  20. Affected versionversion=b3ddf6ba5e28a57729fff1605ae08e21be5c92e3
  21. Affected versionversion=e50fe43e3062e18846e99d9646b9c07b097eb1ed
  22. Affected versionversion=ea54176e5821936d109bb45dc2c19bd53559e735 <b96bd2c3db26ad0daec5b78c85c098b53900e2e1
  23. Affected versionversion=fbbfd55a40d5d0806b59ee0403c75d5ac517533f

What conditions does exploitation require?

Attack vectorlocal
Required privilegesauthenticated

What is affected?

The Linux Kernel Organization · Linuxversion=059b1480105478c5f68cf664301545b8cad6a7cf; version=4.14.195 <4.15; version=4.19.142 <4.20; version=4.4.234 <4.5; version=4.9.234 <4.10; version=539ae3e03875dacaa9c388aff141ccbb4ef4ecb5; version=5.4.61 <5.4.293; version=5.7.18 <5.8; version=5.8.4 <5.9; version=5872331b3d91820e14716632ebb56b1399b34fe1 <16d9067f00e3a7d1df7c3aa9c20d214923d27e10; version=5872331b3d91820e14716632ebb56b1399b34fe1 <17df39f455f1289319d4d09e4826aa46852ffd17; version=5872331b3d91820e14716632ebb56b1399b34fe1 <2883e9e74f73f9265e5f8d1aaaa89034b308e433; version=5872331b3d91820e14716632ebb56b1399b34fe1 <2eeb1085bf7bd5c7ba796ca4119925fa5d336a3f; version=5872331b3d91820e14716632ebb56b1399b34fe1 <35d0aa6db9d93307085871ceab8a729594a98162; version=5872331b3d91820e14716632ebb56b1399b34fe1 <515c34cff899eb5dae6aa7eee01c1295b07d81af; version=5872331b3d91820e14716632ebb56b1399b34fe1 <94824ac9a8aaf2fb3c54b4bdde842db80ffa555d; version=5872331b3d91820e14716632ebb56b1399b34fe1 <ab0cc5c25552ae0d20eae94b40a93be11b080fc5; version=5.9; version=88e79f7a9841278fa8ff7ff6178bad12da002ffc; version=b3ddf6ba5e28a57729fff1605ae08e21be5c92e3; version=e50fe43e3062e18846e99d9646b9c07b097eb1ed; version=ea54176e5821936d109bb45dc2c19bd53559e735 <b96bd2c3db26ad0daec5b78c85c098b53900e2e1; version=fbbfd55a40d5d0806b59ee0403c75d5ac517533f

Published CVSS scores

5.5NIST NVDCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
7.8kernel.orgCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

CVSS describes severity. EPSS estimates exploitation probability.

Attacks

What attackers are doing with it

Daily unique IPs observed by Shadowserver honeypots for known exploited vulnerabilities (KEVs). Missing observations do not establish an absence of attacks.

Daily unique IPsNo honeypot observations are available for this CVE in the selected window.

No observations available

Sep 10, 2026Sep 16, 2026
Latest reporting daySep 16, 2026
Latest daily unique IPsUnavailable
Prior 30-day averageUnavailable
SourceShadowserver honeypots (KEV)
Vectorlocal
Privilegesauthenticated
Known exploitationUnconfirmed
Public exploitUnconfirmed

Weakness, pattern, technique

CWE-193Off-by-one Error

Public exploit references

No public exploit references are available in this record.

Labels summarize the accepted research assessment. They do not indicate a test against your environment.

Technologies

Your stack

See the directory against your own environment.

Your stack

Check the software in your environment

Book a demo to see how Hinoki identifies affected software and validates exploitability in your environment.

Book a demo