---
id: CVE-2025-71161
title: 'dm-verity: disable recursive forward error correction'
summary: |-
  In the Linux kernel, the following vulnerability has been resolved:

  dm-verity: disable recursive forward error correction

  There are two problems with the recursive correction:

  1. It may cause denial-of-service. In fec_read_bufs, there…
severity: high
cvss: 7.5
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H'
cvssSource: cna
vendor: Linux
product: Linux
affected:
  - >-
    Linux >= a739ff3f543afbb4a041c16cd0182c8e8d366e70 <
    8b821ca892cfeeaf0bedc9fc72717294f67144d5
  - >-
    Linux >= a739ff3f543afbb4a041c16cd0182c8e8d366e70 <
    e227d2b229c7529bd98d348efc55262ccf24ab35
  - >-
    Linux >= a739ff3f543afbb4a041c16cd0182c8e8d366e70 <
    897d9006e75f46f8bd7df78faa424327ae6a4bcf
  - >-
    Linux >= a739ff3f543afbb4a041c16cd0182c8e8d366e70 <
    4220cb37406915c926c0e4a3dbab77cd9cceeb1e
  - >-
    Linux >= a739ff3f543afbb4a041c16cd0182c8e8d366e70 <
    232948cf600fba69aff36b25d85ef91a73a35756
  - >-
    Linux >= a739ff3f543afbb4a041c16cd0182c8e8d366e70 <
    d9f3e47d3fae0c101d9094bc956ed24e7a0ee801
  - Linux 4.5
published: '2026-01-23'
updated: '2026-09-08'
sourceUpdated: '2026-09-08T08:44:03.288Z'
source: CVEORG
sourceUrl: 'https://www.cve.org/CVERecord?id=CVE-2025-71161'
references:
  - url: 'https://git.kernel.org/stable/c/8b821ca892cfeeaf0bedc9fc72717294f67144d5'
  - url: 'https://git.kernel.org/stable/c/e227d2b229c7529bd98d348efc55262ccf24ab35'
  - url: 'https://git.kernel.org/stable/c/897d9006e75f46f8bd7df78faa424327ae6a4bcf'
  - url: 'https://git.kernel.org/stable/c/4220cb37406915c926c0e4a3dbab77cd9cceeb1e'
  - url: 'https://git.kernel.org/stable/c/232948cf600fba69aff36b25d85ef91a73a35756'
  - url: 'https://git.kernel.org/stable/c/d9f3e47d3fae0c101d9094bc956ed24e7a0ee801'
tags:
  - cve.org
epss: 0.00379
epssPercentile: 0.2915
ingestedAt: '2026-09-08T15:33:26.994Z'
---

## Overview

In the Linux kernel, the following vulnerability has been resolved:

dm-verity: disable recursive forward error correction

There are two problems with the recursive correction:

1. It may cause denial-of-service. In fec_read_bufs, there is a loop that
has 253 iterations. For each iteration, we may call verity_hash_for_block
recursively. There is a limit of 4 nested recursions - that means that
there may be at most 253^4 (4 billion) iterations. Red Hat QE team
actually created an image that pushes dm-verity to this limit - and this
image just makes the udev-worker process get stuck in the 'D' state.

2. It doesn't work. In fec_read_bufs we store data into the variable
"fio->bufs", but fio bufs is shared between recursive invocations, if
"verity_hash_for_block" invoked correction recursively, it would
overwrite partially filled fio->bufs.

## Affected

- `Linux >= a739ff3f543afbb4a041c16cd0182c8e8d366e70 < 8b821ca892cfeeaf0bedc9fc72717294f67144d5`
- `Linux >= a739ff3f543afbb4a041c16cd0182c8e8d366e70 < e227d2b229c7529bd98d348efc55262ccf24ab35`
- `Linux >= a739ff3f543afbb4a041c16cd0182c8e8d366e70 < 897d9006e75f46f8bd7df78faa424327ae6a4bcf`
- `Linux >= a739ff3f543afbb4a041c16cd0182c8e8d366e70 < 4220cb37406915c926c0e4a3dbab77cd9cceeb1e`
- `Linux >= a739ff3f543afbb4a041c16cd0182c8e8d366e70 < 232948cf600fba69aff36b25d85ef91a73a35756`
- `Linux >= a739ff3f543afbb4a041c16cd0182c8e8d366e70 < d9f3e47d3fae0c101d9094bc956ed24e7a0ee801`
- `Linux 4.5`

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
