Answer in brief
CVE-2025-40190 records a Unknown severity vulnerability in ext4: guard against EA inode refcount underflow in xattr update. The current sources do not mark it as known exploited. The current feed maps Linux/Linux (generic). Check affected ranges and fixed versions before updating.
Analysis pending evidence review
HOL Guard separates source facts from reviewed analysis. See the methodology.
Answer in brief
CVE-2025-40190 records a Unknown severity vulnerability in ext4: guard against EA inode refcount underflow in xattr update. The current sources do not mark it as known exploited. The current feed maps Linux/Linux (generic). Check affected ranges and fixed versions before updating.
Analysis pending evidence review
HOL Guard separates source facts from reviewed analysis. See the methodology.
A CVSS score is not reported in the current record. The current sources do not mark it as known exploited. Treat this as a source-backed prioritization signal, not a statement about your environment.
Analysis status
Analysis pending evidence review
Factual feed record only; HOL analysis is not approved for indexing. Read the methodology.
The current feed maps Linux/Linux (generic). Check affected ranges and fixed versions before updating.
| Package | Affected range | Fixed version |
|---|---|---|
| Linux/Linuxgeneric | >=1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 <ea39e712c2f5ae148ee5515798ae03523673e002 || >=1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 <1cfb3e4ddbdc8e02e637b8852540bd4718bf4814 || >=1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 <505e69f76ac497e788f4ea0267826ec7266b40c8 || >=1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 <3d6269028246f4484bfed403c947a114bb583631 || >=1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 <79ea7f3e11effe1bd9e753172981d9029133a278 || >=1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 <6b879c4c6bbaab03c0ad2a983953bd1410bb165e || >=1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 <440b003f449a4ff2a00b08c8eab9ba5cd28f3943 || >=1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 <57295e835408d8d425bef58da5253465db3d6888 || >=0 <5.4.301 || >=0 <5.10.246 || >=0 <5.15.195 || >=0 <6.1.157 || >=0 <6.6.113 || >=0 <6.12.54 || >=0 <6.17.4 | ea39e712c2f5ae148ee5515798ae03523673e002, 1cfb3e4ddbdc8e02e637b8852540bd4718bf4814, 505e69f76ac497e788f4ea0267826ec7266b40c8, 3d6269028246f4484bfed403c947a114bb583631, 79ea7f3e11effe1bd9e753172981d9029133a278, 6b879c4c6bbaab03c0ad2a983953bd1410bb165e, 440b003f449a4ff2a00b08c8eab9ba5cd28f3943, 57295e835408d8d425bef58da5253465db3d6888, 5.4.301, 5.10.246, 5.15.195, 6.1.157, 6.6.113, 6.12.54, 6.17.4 |
Published upstream
Nov 12, 2025
Evidence: source:cvelist:source_dates:source-dates:recordSource modified
Aug 5, 2026
Evidence: source:cvelist:source_dates:source-dates:recordFirst seen by HOL
Aug 5, 2026
In the Linux kernel, the following vulnerability has been resolved: ext4: guard against EA inode refcount underflow in xattr update syzkaller found a path where ext4_xattr_inode_update_ref() reads an EA inode refcount that is already <= 0 and then applies ref_change (often -1). That lets the refcount underflow and we proceed with a bogus value, triggering errors like: EXT4-fs error: EA inode <n> ref underflow: ref_count=-1 ref_change=-1 EXT4-fs warning: ea_inode dec ref err=-117 Make the invariant explicit: if the current refcount is non-positive, treat this as on-disk corruption, emit ext4_error_inode(), and fail the operation with -EFSCORRUPTED instead of updating the refcount. Delete the WARN_ONCE() as negative refcounts are now impossible; keep error reporting in ext4_error_inode(). This prevents the underflow and the follow-on orphan/cleanup churn.
Quoted source text, attributed separately from HOL analysis.
A CVSS score is not reported in the current record. The current sources do not mark it as known exploited. Treat this as a source-backed prioritization signal, not a statement about your environment.
Analysis status
Analysis pending evidence review
Factual feed record only; HOL analysis is not approved for indexing. Read the methodology.
The current feed maps Linux/Linux (generic). Check affected ranges and fixed versions before updating.
| Package | Affected range | Fixed version |
|---|---|---|
| Linux/Linuxgeneric | >=1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 <ea39e712c2f5ae148ee5515798ae03523673e002 || >=1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 <1cfb3e4ddbdc8e02e637b8852540bd4718bf4814 || >=1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 <505e69f76ac497e788f4ea0267826ec7266b40c8 || >=1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 <3d6269028246f4484bfed403c947a114bb583631 || >=1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 <79ea7f3e11effe1bd9e753172981d9029133a278 || >=1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 <6b879c4c6bbaab03c0ad2a983953bd1410bb165e || >=1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 <440b003f449a4ff2a00b08c8eab9ba5cd28f3943 || >=1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 <57295e835408d8d425bef58da5253465db3d6888 || >=0 <5.4.301 || >=0 <5.10.246 || >=0 <5.15.195 || >=0 <6.1.157 || >=0 <6.6.113 || >=0 <6.12.54 || >=0 <6.17.4 | ea39e712c2f5ae148ee5515798ae03523673e002, 1cfb3e4ddbdc8e02e637b8852540bd4718bf4814, 505e69f76ac497e788f4ea0267826ec7266b40c8, 3d6269028246f4484bfed403c947a114bb583631, 79ea7f3e11effe1bd9e753172981d9029133a278, 6b879c4c6bbaab03c0ad2a983953bd1410bb165e, 440b003f449a4ff2a00b08c8eab9ba5cd28f3943, 57295e835408d8d425bef58da5253465db3d6888, 5.4.301, 5.10.246, 5.15.195, 6.1.157, 6.6.113, 6.12.54, 6.17.4 |
Published upstream
Nov 12, 2025
Evidence: source:cvelist:source_dates:source-dates:recordSource modified
Aug 5, 2026
Evidence: source:cvelist:source_dates:source-dates:recordFirst seen by HOL
Aug 5, 2026
In the Linux kernel, the following vulnerability has been resolved: ext4: guard against EA inode refcount underflow in xattr update syzkaller found a path where ext4_xattr_inode_update_ref() reads an EA inode refcount that is already <= 0 and then applies ref_change (often -1). That lets the refcount underflow and we proceed with a bogus value, triggering errors like: EXT4-fs error: EA inode <n> ref underflow: ref_count=-1 ref_change=-1 EXT4-fs warning: ea_inode dec ref err=-117 Make the invariant explicit: if the current refcount is non-positive, treat this as on-disk corruption, emit ext4_error_inode(), and fail the operation with -EFSCORRUPTED instead of updating the refcount. Delete the WARN_ONCE() as negative refcounts are now impossible; keep error reporting in ext4_error_inode(). This prevents the underflow and the follow-on orphan/cleanup churn.
Quoted source text, attributed separately from HOL analysis.