CVE-2025-70100
Estado: ModificadaMedia (5.5)—
A divide-by-zero vulnerability in the ext4_block_set_lb_size function in src/ext4_blockdev.c of the lwext4 1.0.0 library allows attackers to cause a denial of service by providing a malformed ext4 filesystem image that results in a zero logical block size. The vulnerability is triggered during mount or image processing and leads to a Floating-Point Exception (FPE) under sanitizers or a runtime crash in standard builds due to missing validation of lb_size.
CVSS
- Versión: 3.1
- Vector: CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
- Puntuación base: 5.5
Probabilidad de explotación (EPSS)
- Probabilidad de explotación en los próximos 30 días: 0.16%
- Percentil entre todas las CVEs puntuadas: 5
- Fecha de la puntuación: 6/10/2026
EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).
Tecnologías afectadas (1)
CWE
- CWE-369
Referencias
JSON original (NVD)
Mostrar
{
"id": "CVE-2025-70100",
"cveTags": [],
"metrics": {
"ssvcV203": [
{
"source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"ssvcData": {
"id": "CVE-2025-70100",
"role": "CISA Coordinator",
"options": [
{
"exploitation": "poc"
},
{
"automatable": "no"
},
{
"technicalImpact": "partial"
}
],
"version": "2.0.3",
"timestamp": "2026-06-03T17:33:43.633264Z"
}
}
],
"cvssMetricV31": [
{
"type": "Secondary",
"source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"cvssData": {
"scope": "UNCHANGED",
"version": "3.1",
"baseScore": 5.5,
"attackVector": "LOCAL",
"baseSeverity": "MEDIUM",
"vectorString": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H",
"integrityImpact": "NONE",
"userInteraction": "REQUIRED",
"attackComplexity": "LOW",
"availabilityImpact": "HIGH",
"privilegesRequired": "NONE",
"confidentialityImpact": "NONE"
},
"impactScore": 3.6,
"exploitabilityScore": 1.8
}
]
},
"affected": [
{
"source": "cve@mitre.org",
"affectedData": [
{
"vendor": "n/a",
"product": "n/a",
"versions": [
{
"status": "affected",
"version": "n/a"
}
]
}
]
}
],
"published": "2026-06-03T14:16:31.217",
"references": [
{
"url": "https://github.com/gkostka/lwext4/issues/90",
"tags": [
"Exploit",
"Issue Tracking",
"Patch"
],
"source": "cve@mitre.org"
},
{
"url": "https://github.com/sigdevel/pocs/blob/main/res/lwext4/2/sig8_2_lwext4_ext4_blockdev_c_127",
"tags": [
"Exploit"
],
"source": "cve@mitre.org"
},
{
"url": "https://infosec.exchange/@sigdevel/116668952003072580",
"tags": [
"Exploit",
"Patch",
"Third Party Advisory"
],
"source": "cve@mitre.org"
},
{
"url": "http://www.openwall.com/lists/oss-security/2026/06/29/5",
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "https://github.com/gkostka/lwext4/issues/90",
"tags": [
"Exploit",
"Issue Tracking",
"Patch"
],
"source": "134c704f-9b21-4f2e-91b3-4a467353bcc0"
}
],
"vulnStatus": "Modified",
"weaknesses": [
{
"type": "Secondary",
"source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"description": [
{
"lang": "en",
"value": "CWE-369"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "A divide-by-zero vulnerability in the ext4_block_set_lb_size function in src/ext4_blockdev.c of the lwext4 1.0.0 library allows attackers to cause a denial of service by providing a malformed ext4 filesystem image that results in a zero logical block size. The vulnerability is triggered during mount or image processing and leads to a Floating-Point Exception (FPE) under sanitizers or a runtime crash in standard builds due to missing validation of lb_size."
},
{
"lang": "es",
"value": "Una vulnerabilidad de división por cero en la función ext4_block_set_lb_size en src/ext4_blockdev.c de la biblioteca lwext4 1.0.0 permite a los atacantes causar una denegación de servicio al proporcionar una imagen de sistema de archivos ext4 malformada que resulta en un tamaño de bloque lógico cero. La vulnerabilidad se activa durante el montaje o el procesamiento de la imagen y conduce a una Excepción de Punto Flotante (FPE) bajo sanitizadores o un fallo en tiempo de ejecución en compilaciones estándar debido a la falta de validación de lb_size."
}
],
"lastModified": "2026-07-22T19:10:00.120",
"configurations": [
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:a:gkostka:lwext4:1.0.0:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "70BC7F76-4450-4CC3-8C76-64CBB6EC4740"
}
],
"operator": "OR"
}
]
}
],
"sourceIdentifier": "cve@mitre.org"
}