CVE-2025-21679 – Linux Kernel Btrfs Null Pointer Dereference

The following table lists the changes that have been made to the
CVE-2025-21679 vulnerability over time.

Vulnerability history details can be useful for understanding the evolution
of a vulnerability, and for identifying the most recent changes that may
impact the vulnerability’s severity, exploitability, or other characteristics.

  • New CVE Received
    by 416baaa9-dc9f-4396-8d5f-8c081fb06d67

    Jan. 31, 2025

    Action Type Old Value New Value
    Added Description In the Linux kernel, the following vulnerability has been resolved:

    btrfs: add the missing error handling inside get_canonical_dev_path

    Inside function get_canonical_dev_path(), we call d_path() to get the
    final device path.

    But d_path() can return error, and in that case the next strscpy() call
    will trigger an invalid memory access.

    Add back the missing error handling for d_path().

    Added Reference https://git.kernel.org/stable/c/d0fb5741932b831eded49bfaaf33353e96200d6d
    Added Reference https://git.kernel.org/stable/c/fe4de594f7a2e9bc49407de60fbd20809fad4192
Share the Post:

Related Posts