Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Wed, 03 Jun 2026 02:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Gkostka
Gkostka lwext4 |
|
| Vendors & Products |
Gkostka
Gkostka lwext4 |
Tue, 02 Jun 2026 18:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Title | NULL Pointer Dereference in lwext4 Causing Denial of Service on Malformed EXT4 Filesystem Images |
Tue, 02 Jun 2026 16:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
cvssV3_1
|
Mon, 01 Jun 2026 21:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Title | NULL Pointer Dereference in lwext4 Causing Denial of Service on Malformed EXT4 Filesystem Images | |
| Weaknesses | CWE-476 |
Mon, 01 Jun 2026 20:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | A NULL pointer dereference in the ext4_dir_en_get_name_len function in include/ext4_dir.h of lwext4 1.0.0 allows attackers to cause a denial of service by supplying a specially crafted EXT4 filesystem image with malformed directory entries. During directory iteration, the code may fail to validate the directory entry pointer before accessing the name_len field, resulting in a segmentation fault. This affects versions based on (or equivalent to) the 2016-era codebase (1.0.0). | |
| References |
|
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2026-06-29T19:34:43.285Z
Reserved: 2026-01-09T00:00:00.000Z
Link: CVE-2025-70099
Updated: 2026-06-29T19:34:43.285Z
Status : Deferred
Published: 2026-06-01T21:16:24.187
Modified: 2026-06-02T16:16:30.917
Link: CVE-2025-70099
No data.
OpenCVE Enrichment
Updated: 2026-06-02T20:55:13Z