{ "dataType": "CVE_RECORD", "dataVersion": "5.2", "cveMetadata": { "cveId": "CVE-2025-22019", "assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67", "state": "PUBLISHED", "assignerShortName": "Linux", "dateReserved": "2024-12-29T08:45:45.806Z", "datePublished": "2025-04-16T10:20:36.342Z", "dateUpdated": "2026-08-05T11:56:01.490Z" }, "containers": { "cna": { "providerMetadata": { "orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67", "shortName": "Linux", "dateUpdated": "2026-08-05T11:56:01.490Z" }, "descriptions": [ { "lang": "en", "value": "In the Linux kernel, the following vulnerability has been resolved:\n\nbcachefs: bch2_ioctl_subvolume_destroy() fixes\n\nbch2_evict_subvolume_inodes() was getting stuck - due to incorrectly\npruning the dcache.\n\nAlso, fix missing permissions checks." } ], "metrics": [ { "cvssV3_1": { "version": "3.1", "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:H/A:H", "baseScore": 7.3, "baseSeverity": "HIGH" }, "scenarios": [ { "lang": "en", "value": "AV:L - The bug is reached through `ioctl(BCH_IOCTL_SUBVOLUME_DESTROY)` on any open file descriptor belonging to a mounted bcachefs filesystem, which requires local access to the system. There is no network-facing path into `bch2_fs_file_ioctl()`.\nAC:L - The attacker deterministically triggers both defects with a single ioctl call — no race, no memory-layout dependence, no timing window; the dcache state that wedges `bch2_evict_subvolume_inodes()` is created by the attacker simply by walking into the subvolume beforehand. No conditions lie outside the attacker's control.\nPR:L - `BCH_IOCTL_SUBVOLUME_DESTROY` has no `capable()` check and, before this fix, no `inode_permission()` check, so an ordinary unprivileged local user needs only an fd on the bcachefs mount plus search (`MAY_EXEC`) permission along the path to the victim subvolume. No CAP_SYS_ADMIN, no user-namespace trick, and no ownership of or write access to the target is required.\nUI:N - The attacker issues the ioctl directly with no action by any other user; the mounted bcachefs filesystem is an ambient system configuration, not a victim-performed step at exploit time.\nS:U - The vulnerable code and the impacted resources (kernel filesystem state, on-disk subvolume data) are managed by the same security authority — the kernel. This is a standard in-kernel DAC-bypass/DoS with no VM, IOMMU, or sandbox boundary crossed.\nC:L - There is no direct arbitrary-read primitive, but the DAC bypass has bounded disclosure consequences: after destroying a root- or other-user-owned subvolume in a directory the attacker can write to, the attacker can recreate the path and have a privileged process deposit sensitive data into attacker-controlled storage, and the non-invalidated dcache subtree leaves stale dentries/inodes referencing a freed subvolume ID that can be reused by another user's newly created subvolume.\nI:H - An unprivileged user can permanently destroy any subvolume they can merely traverse to — including root-owned subvolumes and other users' mode-0700 subvolumes — bypassing all ownership, write-permission, sticky-bit and non-empty-directory protections, which is unauthorized destruction of arbitrary data on the filesystem. The stale, still-hashed dentry subtree over a deleted subvolume additionally permits writes through inodes whose subvolume ID may be reused.\nA:H - The `d_delete()` bug leaves `bch2_evict_subvolume_inodes()` stuck in `TASK_UNINTERRUPTIBLE`, producing an unkillable D-state kworker that holds `BCH_WRITE_REF_snapshot_delete_pagecache` forever — unmount and read-only transitions hang, all further subvolume deletions stall, and recovery requires a reboot. Independently, arbitrary destruction of subvolumes (e.g. one holding `/home` or a database) is total loss of the affected data." } ] } ], "affected": [ { "product": "Linux", "vendor": "Linux", "defaultStatus": "unaffected", "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git", "programFiles": [ "fs/bcachefs/fs-ioctl.c" ], "versions": [ { "version": "1c6fdbd8f2465ddfb73a01ec620cbf3d14044e1a", "lessThan": "9e6e83e1e2d01b99e70cd7812d7f758a8def9fc8", "status": "affected", "versionType": "git" }, { "version": "1c6fdbd8f2465ddfb73a01ec620cbf3d14044e1a", "lessThan": "82383abd39abd635511b8956284a5cc8134c4dc1", "status": "affected", "versionType": "git" }, { "version": "1c6fdbd8f2465ddfb73a01ec620cbf3d14044e1a", "lessThan": "558317a5c61045d460a37372181e7b43c0c002bb", "status": "affected", "versionType": "git" }, { "version": "1c6fdbd8f2465ddfb73a01ec620cbf3d14044e1a", "lessThan": "707549600c4a012ed71c0204a7992a679880bf33", "status": "affected", "versionType": "git" } ] }, { "product": "Linux", "vendor": "Linux", "defaultStatus": "affected", "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git", "programFiles": [ "fs/bcachefs/fs-ioctl.c" ], "versions": [ { "version": "6.7", "status": "affected" }, { "version": "0", "lessThan": "6.7", "status": "unaffected", "versionType": "semver" }, { "version": "6.12.22", "lessThanOrEqual": "6.12.*", "status": "unaffected", "versionType": "semver" }, { "version": "6.13.10", "lessThanOrEqual": "6.13.*", "status": "unaffected", "versionType": "semver" }, { "version": "6.14.2", "lessThanOrEqual": "6.14.*", "status": "unaffected", "versionType": "semver" }, { "version": "6.15", "lessThanOrEqual": "*", "status": "unaffected", "versionType": "original_commit_for_fix" } ] } ], "cpeApplicability": [ { "nodes": [ { "operator": "OR", "negate": false, "cpeMatch": [ { "vulnerable": true, "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*", "versionStartIncluding": "6.7", "versionEndExcluding": "6.12.22" }, { "vulnerable": true, "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*", "versionStartIncluding": "6.7", "versionEndExcluding": "6.13.10" }, { "vulnerable": true, "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*", "versionStartIncluding": "6.7", "versionEndExcluding": "6.14.2" }, { "vulnerable": true, "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*", "versionStartIncluding": "6.7", "versionEndExcluding": "6.15" } ] } ] } ], "references": [ { "url": "https://git.kernel.org/stable/c/9e6e83e1e2d01b99e70cd7812d7f758a8def9fc8" }, { "url": "https://git.kernel.org/stable/c/82383abd39abd635511b8956284a5cc8134c4dc1" }, { "url": "https://git.kernel.org/stable/c/558317a5c61045d460a37372181e7b43c0c002bb" }, { "url": "https://git.kernel.org/stable/c/707549600c4a012ed71c0204a7992a679880bf33" } ], "title": "bcachefs: bch2_ioctl_subvolume_destroy() fixes", "x_generator": { "engine": "bippy-1.2.0" } } } }