CVE-2025-71161

Updated on 23 Jan 2026

Severity

5.5 Medium severity

Details

CVSS score
5.5
CVSS vector
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H

Overview

About vulnerability

In the Linux kernel, the following vulnerability has been resolved:

dm-verity: disable recursive forward error correction

There are two problems with the recursive correction:

  1. It may cause denial-of-service. In fec_read_bufs, there is a loop that has 253 iterations. For each iteration, we may call verity_hash_for_block recursively. There is a limit of 4 nested recursions - that means that there may be at most 253^4 (4 billion) iterations. Red Hat QE team actually created an image that pushes dm-verity to this limit - and this image just makes the udev-worker process get stuck in the ‘D’ state.

  2. It doesn’t work. In fec_read_bufs we store data into the variable “fio->bufs”, but fio bufs is shared between recursive invocations, if “verity_hash_for_block” invoked correction recursively, it would overwrite partially filled fio->bufs.

Details

Fixes

KernelCare state

Live-patch status from KernelCare for each operating system.

Operating system Status Covered kernels
AlmaLinux 9.2 ESU Planned
AlmaLinux 9.6 ESU Planned
Amazon Linux 2023 Planned
Debian 12 Planned
Debian 13 Planned
Ubuntu 22.04 Planned
Ubuntu 24.04 Planned