Linux Kernel Directory H-Tree Cycle Vulnerability in ext4 File System

Vulnerability

A vulnerability in the Linux kernel's ext4 file system allows for the creation of cycles in the directory h-tree, which can lead to kernel memory corruption. This issue arises when a maliciously crafted filesystem introduces cycles in the h-tree of a directory, causing the kernel to improperly handle tree nodes during operations like node splitting. As a result, the kernel may access unallocated memory, potentially leading to further exploitation.

Impact

Exploitation of this vulnerability can cause kernel memory corruption, with the possibility of accessing unallocated memory, which could be exploited to execute arbitrary code or cause a denial-of-service condition by crashing the system.

Added: Jun 9, 2025, 7:46 PM
Updated: Jun 9, 2025, 7:46 PM

Vulnerability Rating

Custom Algorithm
spread
9.0
impact
2.5
exploitability
5.3
remediation
0.0
relevance
0.0
threat
3.2
urgency
2.9
incentive
1.7

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.