{"id":"CVE-2025-22124","title":"md/md-bitmap: fix wrong bitmap_limit for clustermd when write sb","summary":"In the Linux kernel, the following vulnerability has been resolved:\n\nmd/md-bitmap: fix wrong bitmap_limit for clustermd when write sb\n\nIn clustermd, separate write-intent-bitmaps are used for each cluster\nnode:\n\n0                    4k  …","severity":"high","cvss":7.8,"cvssVector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","cvssSource":"cna","vendor":"Linux","product":"Linux","affected":["Linux >= 655cc01889fa9b65441922565cddee64af49e6d6 < 5eaf57fdfa37c869e61e9908e03edd707f9145b8","Linux >= ab99a87542f194f28e2364a42afbf9fb48b1c724 < 60196f92bbc7901eb5cfa5d456651b87ea50a4a3","Linux >= ab99a87542f194f28e2364a42afbf9fb48b1c724 < bc3a9788961631359527763d7e1fcf26554c7cb1","Linux >= ab99a87542f194f28e2364a42afbf9fb48b1c724 < 6130825f34d41718c98a9b1504a79a23e379701e","Linux 5600d6013c634c2b6b6c6c55c8ecb50c3a6211f2","Linux >= 6.6.44 < 6.6.157","Linux >= 6.10.3 < 6.11","Linux 6.11"],"published":"2025-04-16","updated":"2026-09-14","sourceUpdated":"2026-09-14T11:57:56.837Z","source":"CVEORG","sourceUrl":"https://www.cve.org/CVERecord?id=CVE-2025-22124","references":[{"url":"https://git.kernel.org/stable/c/5eaf57fdfa37c869e61e9908e03edd707f9145b8"},{"url":"https://git.kernel.org/stable/c/60196f92bbc7901eb5cfa5d456651b87ea50a4a3"},{"url":"https://git.kernel.org/stable/c/bc3a9788961631359527763d7e1fcf26554c7cb1"},{"url":"https://git.kernel.org/stable/c/6130825f34d41718c98a9b1504a79a23e379701e"}],"tags":["cve.org"],"epss":0.00198,"epssPercentile":0.09915,"ingestedAt":"2026-09-14T15:23:07.459Z","slug":"CVE-2025-22124","body":"## Overview\n\nIn the Linux kernel, the following vulnerability has been resolved:\n\nmd/md-bitmap: fix wrong bitmap_limit for clustermd when write sb\n\nIn clustermd, separate write-intent-bitmaps are used for each cluster\nnode:\n\n0                    4k                     8k                    12k\n-------------------------------------------------------------------\n| idle                | md super            | bm super [0] + bits |\n| bm bits[0, contd]   | bm super[1] + bits  | bm bits[1, contd]   |\n| bm super[2] + bits  | bm bits [2, contd]  | bm super[3] + bits  |\n| bm bits [3, contd]  |                     |                     |\n\nSo in node 1, pg_index in __write_sb_page() could equal to\nbitmap->storage.file_pages. Then bitmap_limit will be calculated to\n0. md_super_write() will be called with 0 size.\nThat means the first 4k sb area of node 1 will never be updated\nthrough filemap_write_page().\nThis bug causes hang of mdadm/clustermd_tests/01r1_Grow_resize.\n\nHere use (pg_index % bitmap->storage.file_pages) to make calculation\nof bitmap_limit correct.\n\n## Affected\n\n- `Linux >= 655cc01889fa9b65441922565cddee64af49e6d6 < 5eaf57fdfa37c869e61e9908e03edd707f9145b8`\n- `Linux >= ab99a87542f194f28e2364a42afbf9fb48b1c724 < 60196f92bbc7901eb5cfa5d456651b87ea50a4a3`\n- `Linux >= ab99a87542f194f28e2364a42afbf9fb48b1c724 < bc3a9788961631359527763d7e1fcf26554c7cb1`\n- `Linux >= ab99a87542f194f28e2364a42afbf9fb48b1c724 < 6130825f34d41718c98a9b1504a79a23e379701e`\n- `Linux 5600d6013c634c2b6b6c6c55c8ecb50c3a6211f2`\n- `Linux >= 6.6.44 < 6.6.157`\n- `Linux >= 6.10.3 < 6.11`\n- `Linux 6.11`\n\n## Remediation\n\nRefer to the linked advisories for vendor-supplied fixes and affected version ranges.","depth":"twilight","depthScore":43,"depthScoreParts":{"impact":42.9,"likelihood":0,"exploitation":0,"ransomware":0},"changes":[]}