VYPR
High severity7.8NVD Advisory· Published Apr 16, 2025· Updated Jul 30, 2026

CVE-2025-22079

CVE-2025-22079

Description

In the Linux kernel, the following vulnerability has been resolved:

ocfs2: validate l_tree_depth to avoid out-of-bounds access

The l_tree_depth field is 16-bit (__le16), but the actual maximum depth is limited to OCFS2_MAX_PATH_DEPTH.

Add a check to prevent out-of-bounds access if l_tree_depth has an invalid value, which may occur when reading from a corrupted mounted disk [1].

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected products

4
  • Linux/Kernel3 versions
    cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*+ 2 more
    • cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*range: >=2.6.16,<5.4.292
    • (no CPE)
    • (no CPE)range: 2.6.16
  • osv-coords
    Range: >= 2.6.16, < 5.4.292

Patches

Vulnerability mechanics

References

11

News mentions

0

No linked articles in our index yet.