{"id":"DEBIAN-CVE-2025-22036","details":"In the Linux kernel, the following vulnerability has been resolved:  exfat: fix random stack corruption after get_block  When get_block is called with a buffer_head allocated on the stack, such as do_mpage_readpage, stack corruption due to buffer_head UAF may occur in the following race condition situation.       \u003cCPU 0\u003e                      \u003cCPU 1\u003e mpage_read_folio   \u003c\u003cbh on stack\u003e\u003e   do_mpage_readpage     exfat_get_block       bh_read         __bh_read \t  get_bh(bh)           submit_bh           wait_on_buffer                               ...                               end_buffer_read_sync                                 __end_buffer_read_notouch                                    unlock_buffer           \u003c\u003ckeep going\u003e\u003e         ...       ...     ...   ... \u003c\u003cbh is not valid out of mpage_read_folio\u003e\u003e    .    . another_function   \u003c\u003cvariable A on stack\u003e\u003e                                    put_bh(bh)                                      atomic_dec(bh-\u003eb_count)   * stack corruption here *  This patch returns -EAGAIN if a folio does not have buffers when bh_read needs to be called. By doing this, the caller can fallback to functions like block_read_full_folio(), create a buffer_head in the folio, and then call get_block again.  Let's do not call bh_read() with on-stack buffer_head.","modified":"2026-08-27T23:05:20.284896575Z","published":"2025-04-16T15:15:56.217Z","upstream":["CVE-2025-22036"],"references":[{"type":"ADVISORY","url":"https://security-tracker.debian.org/tracker/CVE-2025-22036"}],"affected":[{"package":{"name":"linux","ecosystem":"Debian:13","purl":"pkg:deb/debian/linux?arch=source&distro=trixie"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"6.12.25-1"}]}],"ecosystem_specific":{"urgency":"not yet assigned"},"database_specific":{"source":"https://storage.googleapis.com/osv-test-debian-osv/debian-cve-osv/DEBIAN-CVE-2025-22036.json"}},{"package":{"name":"linux","ecosystem":"Debian:14","purl":"pkg:deb/debian/linux?arch=source&distro=forky"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"6.12.25-1"}]}],"ecosystem_specific":{"urgency":"not yet assigned"},"database_specific":{"source":"https://storage.googleapis.com/osv-test-debian-osv/debian-cve-osv/DEBIAN-CVE-2025-22036.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H"}]}