CVE-2025-40361

Source
https://cve.org/CVERecord?id=CVE-2025-40361
Import Source
https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2025-40361.json
JSON Data
https://api.test.osv.dev/v1/vulns/CVE-2025-40361
Downstream
Related
Published
2025-12-16T13:40:00.758Z
Modified
2026-03-12T03:54:40.422433Z
Summary
fs: ext4: change GFP_KERNEL to GFP_NOFS to avoid deadlock
Details

In the Linux kernel, the following vulnerability has been resolved:

fs: ext4: change GFPKERNEL to GFPNOFS to avoid deadlock

The parent function ext4xattrinodelookupcreate already uses GFPNOFS for memory alloction, so the function ext4xattrinodecachefind should use same gfpflag.

Database specific
{
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2025/40xxx/CVE-2025-40361.json",
    "cna_assigner": "Linux"
}
References

Affected packages

Git / git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git

Affected ranges

Type
GIT
Repo
https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git
Events
Introduced
71b565ceff377a52e7d58cd871745cd339447323
Fixed
5e6b27f4e68682aa3db9f83ca04adef89903159b
Fixed
bb7d0d13c6e1f061464d1c425b08348a4e0c235d
Fixed
add8458cac0b33a5e7a6b98457b38baea9600859
Fixed
199ab7b43c5ef7d384f6a08e786e107b3509acda
Fixed
238f7a7356c33a9797a6297c6fdfd87f113b2325
Fixed
009127b0fc013aed193961686c28c2b541a5b2f3
Fixed
1534f72dc2a11ded38b0e0268fbcc0ca24e9fd4a

Database specific

source
"https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2025-40361.json"

Linux / Kernel

Package

Name
Kernel

Affected ranges

Type
ECOSYSTEM
Events
Introduced
5.6.0
Fixed
5.10.247
Type
ECOSYSTEM
Events
Introduced
5.11.0
Fixed
5.15.197
Type
ECOSYSTEM
Events
Introduced
5.16.0
Fixed
6.1.159
Type
ECOSYSTEM
Events
Introduced
6.2.0
Fixed
6.6.117
Type
ECOSYSTEM
Events
Introduced
6.7.0
Fixed
6.12.58
Type
ECOSYSTEM
Events
Introduced
6.13.0
Fixed
6.17.8

Database specific

source
"https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2025-40361.json"