Instituto Nacional de ciberseguridad. Sección Incibe
Instituto Nacional de Ciberseguridad. Sección INCIBE-CERT

CVE-2025-38709

Gravedad CVSS v3.1:
MEDIA
Tipo:
No Disponible / Otro tipo
Fecha de publicación:
04/09/2025
Última modificación:
03/12/2025

Descripción

*** Pendiente de traducción *** In the Linux kernel, the following vulnerability has been resolved:<br /> <br /> loop: Avoid updating block size under exclusive owner<br /> <br /> Syzbot came up with a reproducer where a loop device block size is<br /> changed underneath a mounted filesystem. This causes a mismatch between<br /> the block device block size and the block size stored in the superblock<br /> causing confusion in various places such as fs/buffer.c. The particular<br /> issue triggered by syzbot was a warning in __getblk_slow() due to<br /> requested buffer size not matching block device block size.<br /> <br /> Fix the problem by getting exclusive hold of the loop device to change<br /> its block size. This fails if somebody (such as filesystem) has already<br /> an exclusive ownership of the block device and thus prevents modifying<br /> the loop device under some exclusive owner which doesn&amp;#39;t expect it.

Productos y versiones vulnerables

CPE Desde Hasta
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* 6.6.109 (excluyendo)
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* 6.7 (incluyendo) 6.12.43 (excluyendo)
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* 6.13 (incluyendo) 6.15.11 (excluyendo)
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* 6.16 (incluyendo) 6.16.2 (excluyendo)