CVE-2025-40190 addresses a refcount underflow vulnerability in the ext4 filesystem of the Linux kernel. Specifically, the ext4_xattr_inode_update_ref() function could decrement an already non-positive EA inode refcount, leading to data corruption and system errors. The vulnerability has no assigned CVSS score, but its potential impact involves filesystem corruption, which could lead to data loss or system instability. There is no evidence of active exploitation, public exploit code (Metasploit, Nuclei, ExploitDB), or significant community discussion or media coverage regarding this vulnerability.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 0, < 5.10.246CPE match | cpe:2.3:a:linux:linux_kernel:*:*:*:*:*:*:*:* | ||
>= 0, < 5.15.195CPE match | cpe:2.3:a:linux:linux_kernel:*:*:*:*:*:*:*:* | ||
>= 0, < 5.4.301CPE match | cpe:2.3:a:linux:linux_kernel:*:*:*:*:*:*:*:* | ||
>= 0, < 6.1.157CPE match | cpe:2.3:a:linux:linux_kernel:*:*:*:*:*:*:*:* | ||
>= 0, < 6.12.54CPE match | cpe:2.3:a:linux:linux_kernel:*:*:*:*:*:*:*:* |
CVSS data has not been published for this CVE.
No media coverage found for this CVE.