Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2025-40190

12
FAUCET Score

CVE-2025-40190 addresses a refcount underflow vulnerability in the ext4 filesystem of the Linux kernel. Specifically, the ext4_xattr_inode_update_ref() function could decrement an already non-positive EA inode refcount, leading to data corruption and system errors. The vulnerability has no assigned CVSS score, but its potential impact involves filesystem corruption, which could lead to data loss or system instability. There is no evidence of active exploitation, public exploit code (Metasploit, Nuclei, ExploitDB), or significant community discussion or media coverage regarding this vulnerability.

Impacted Technologies

VendorProductVersion(s)CPE
>= 0, < 5.10.246CPE match
cpe:2.3:a:linux:linux_kernel:*:*:*:*:*:*:*:*
>= 0, < 5.15.195CPE match
cpe:2.3:a:linux:linux_kernel:*:*:*:*:*:*:*:*
>= 0, < 5.4.301CPE match
cpe:2.3:a:linux:linux_kernel:*:*:*:*:*:*:*:*
>= 0, < 6.1.157CPE match
cpe:2.3:a:linux:linux_kernel:*:*:*:*:*:*:*:*
>= 0, < 6.12.54CPE match
cpe:2.3:a:linux:linux_kernel:*:*:*:*:*:*:*:*

CVSS Data

CVSS data has not been published for this CVE.

Exploit Intelligence

EPSS Score
0.21%
Probability of exploitation in next 30 days
EPSS Percentile
10.8%
Percentile rank of EPSS score among Peer Group
As of 2026-07-28
Model: v2026.06.15

Social Chatter

Media Mentions

No media coverage found for this CVE.

Remediation

Patch Available

Vendor Patches (7)

microsoftpatch availablevia msrc
Product: 20613-17084Fixed in: 6.6.117.1-1
microsoftpatch availablevia msrc
Product: azl3 kernel 6.6.112.1-2 on Azure Linux 3.0Fixed in: 6.6.117.1-1
redhatno patchvia redhat_api
Product: Red Hat Enterprise Linux 9Fixed in: kernel-rt
redhatno patchvia redhat_api
Product: Red Hat Enterprise Linux 8Fixed in: kernel-rt
redhatend of lifevia redhat_api
Product: Red Hat Enterprise Linux 9Fixed in: kernel
redhatend of lifevia redhat_api
Product: Red Hat Enterprise Linux 8Fixed in: kernel
redhatend of lifevia redhat_api
Product: Red Hat Enterprise Linux 10Fixed in: kernel

Vendor Advisories (2)

redhatCVE-2025-40190Moderate

kernel: ext4: guard against EA inode refcount underflow in xattr update

Nov 12, 2025
microsoft2025-Nov/CVE-2025-40190Important

ext4: guard against EA inode refcount underflow in xattr update

Nov 11, 2025

References

git.kernel.org / stable/c/1cfb3e4ddbdc8e02e637b8852540bd4718bf4814
git.kernel.org / stable/c/3d6269028246f4484bfed403c947a114bb583631
git.kernel.org / stable/c/440b003f449a4ff2a00b08c8eab9ba5cd28f3943
git.kernel.org / stable/c/505e69f76ac497e788f4ea0267826ec7266b40c8
git.kernel.org / stable/c/57295e835408d8d425bef58da5253465db3d6888
git.kernel.org / stable/c/6b879c4c6bbaab03c0ad2a983953bd1410bb165e
git.kernel.org / stable/c/79ea7f3e11effe1bd9e753172981d9029133a278
git.kernel.org / stable/c/ea39e712c2f5ae148ee5515798ae03523673e002