
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2025-40205 is a vulnerability discovered in the Linux kernel affecting the btrfs filesystem component. The vulnerability was disclosed on November 12, 2025, and involves a potential out-of-bounds write issue in the btrfsencodefh() function (NVD).
The vulnerability exists in the btrfsencodefh() function which fails to properly handle three different cases when writing to file handles. The function returns either BTRFSFIDSIZENONCONNECTABLE (20 bytes) or BTRFSFIDSIZECONNECTABLE (32 bytes), but can write BTRFSFIDSIZECONNECTABLEROOT (40 bytes) when a parent exists with different root ID, potentially causing an 8-byte out-of-bounds write at fid->parentroot_objectid (NVD).
While the vulnerability represents a potential memory corruption issue, it has been noted that it is not easily triggerable. However, as an out-of-bounds write vulnerability, it could potentially lead to memory corruption if successfully exploited (NVD).
A patch has been developed that ensures the function returns the appropriate size for all three cases and validates that *max_len is large enough before writing any data. The fix has been implemented across multiple Linux distributions, with the vulnerability marked as fixed in most current versions (Debian Security).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."