CVE-2024-25739: Linux Kernel

Medium severity, CVSS 5.5. EPSS: 0.2% chance of exploitation in the next 30 days.

create_empty_lvol in drivers/mtd/ubi/vtbl.c in the Linux kernel through 6.7.4 can attempt to allocate zero bytes, and crash, because of a missing check for ubi->leb_size.

Affected products

  • Linux Linux Kernel: up to and including 6.7.4

Published 2024-02-12. Last modified 2026-06-17.