CVE-2025-22114

MEDIUM

Linux Kernel 6.14 - Filesystem Validation Bypass via btrfs_validate_super()

Title source: llm
STIX 2.1

Description

In the Linux kernel, the following vulnerability has been resolved: btrfs: don't clobber ret in btrfs_validate_super() Commit 2a9bb78cfd36 ("btrfs: validate system chunk array at btrfs_validate_super()") introduces a call to validate_sys_chunk_array() in btrfs_validate_super(), which clobbers the value of ret set earlier. This has the effect of negating the validity checks done earlier, making it so btrfs could potentially try to mount invalid filesystems.

Scores

CVSS v3 5.5
EPSS 0.0016
EPSS Percentile 5.5%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H

Details

Status published
Products (8)
linux/Kernel 6.14.0 - 6.14.2linux
Linux/Linux < 6.14
Linux/Linux 2a9bb78cfd367fdeff74f15b1e98969912292d9e - 9db9c7dd5b4e1d3205137a094805980082c37716
Linux/Linux 2a9bb78cfd367fdeff74f15b1e98969912292d9e - ef6800a2015e706e9852a5ec15263fec9990d012
Linux/Linux 6.14
Linux/Linux 6.14.2 - 6.14.*
Linux/Linux 6.15
linux/linux_kernel 6.14 - 6.14.2
Published Apr 16, 2025
Tracked Since Feb 18, 2026