Threats Tagged 'cve-2025-40205'
View all threats tagged with 'cve-2025-40205'. Filter and sort to focus on specific types of threats.
Stop chasing alerts. Route them.
Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.
Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)
API access activates after upgrading in Console -> Billing.
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.
Filter Threats
Narrow down the results by type, severity, or affected countries
Threats Tagged 'cve-2025-40205'
Click on any threat for detailed analysis and mitigation recommendations
A vulnerability in the Linux kernel's btrfs filesystem code was identified in the function btrfs_encode_fh(). The function improperly handles three cases for file handle sizes, leading to a potential out-of-bounds write of 8 bytes when the parent exists and root IDs differ. This memory corruption issue was resolved by correcting the size returned and validating buffer length before writing. The vulnerability is rated high severity due to its potential impact on confidentiality, integrity, and availability. Join the discussion | GCVE Database | 11/13/2025, 00:30:18 UTC Added: 07/30/2026, 15:50:46 UTC |
In the Linux kernel, the following vulnerability has been resolved: btrfs: avoid potential out-of-bounds in btrfs_encode_fh() The function btrfs_encode_fh() does not properly account for the three cases it handles. Before writing to the file handle (fh), the function only returns to the user BTRFS_FID_SIZE_NON_CONNECTABLE (5 dwords, 20 bytes) or BTRFS_FID_SIZE_CONNECTABLE (8 dwords, 32 bytes). However, when a parent exists and the root ID of the parent and the inode are different, the function writes BTRFS_FID_SIZE_CONNECTABLE_ROOT (10 dwords, 40 bytes). If *max_len is not large enough, this write goes out of bounds because BTRFS_FID_SIZE_CONNECTABLE_ROOT is greater than BTRFS_FID_SIZE_CONNECTABLE originally returned. This results in an 8-byte out-of-bounds write at fid->parent_root_objectid = parent_root_id. A previous attempt to fix this issue was made but was lost. https://lore.kernel.org/all/[email protected]/ Although this issue does not seem to be easily triggerable, it is a potential memory corruption bug that should be fixed. This patch resolves the issue by ensuring the function returns the appropriate size for all three cases and validates that *max_len is large enough before writing any data. Join the discussion | GCVE Database | 11/12/2025, 22:15:00 UTC Added: 07/18/2026, 11:37:01 UTC |
Showing 1 to 2 of 2 results