In the Linux kernel, the following vulnerability has been resolved:
ovl: don't allow datadir only
In theory overlayfs could support upper layer directly referring to a data
layer, but there's no current use case for this.
Originally, when data-only layers were introduced, this wasn't allowed,
only introduced by the "datadir+" feature, but without actually handling
this case, resulting in an Oops.
Fix by disallowing datadir without lowerdir.
References
Configurations
Configuration 1 (hide)
|
History
No history.
Information
Published : 2025-05-09 07:16
Updated : 2025-11-12 20:13
NVD link : CVE-2025-37863
Mitre link : CVE-2025-37863
CVE.ORG link : CVE-2025-37863
JSON object : View
Products Affected
linux
- linux_kernel
CWE
