A divide-by-zero vulnerability in the ext4_block_set_lb_size function in src/ext4_blockdev.c of the lwext4 1.0.0 library allows attackers to cause a denial of service by providing a malformed ext4 filesystem image that results in a zero logical block size. The vulnerability is triggered during mount or image processing and leads to a Floating-Point Exception (FPE) under sanitizers or a runtime crash in standard builds due to missing validation of lb_size.

Project Subscriptions

Vendors Products
Gkostka Subscribe
Advisories

No advisories yet.

Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

Wed, 03 Jun 2026 21:15:00 +0000

Type Values Removed Values Added
Title Divide‑by‑Zero in lwext4 Ext4 Block Size Validation Leading to DoS

Wed, 03 Jun 2026 18:30:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 5.5, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 03 Jun 2026 16:45:00 +0000

Type Values Removed Values Added
First Time appeared Gkostka
Gkostka lwext4
Vendors & Products Gkostka
Gkostka lwext4

Wed, 03 Jun 2026 15:45:00 +0000

Type Values Removed Values Added
Title Divide‑by‑Zero in lwext4 Ext4 Block Size Validation Leading to DoS
Weaknesses CWE-369

Wed, 03 Jun 2026 14:15:00 +0000

Type Values Removed Values Added
Description A divide-by-zero vulnerability in the ext4_block_set_lb_size function in src/ext4_blockdev.c of the lwext4 1.0.0 library allows attackers to cause a denial of service by providing a malformed ext4 filesystem image that results in a zero logical block size. The vulnerability is triggered during mount or image processing and leads to a Floating-Point Exception (FPE) under sanitizers or a runtime crash in standard builds due to missing validation of lb_size.
References

Projects

Sign in to view the affected projects.

cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published:

Updated: 2026-06-03T17:34:25.964Z

Reserved: 2026-01-09T00:00:00.000Z

Link: CVE-2025-70100

cve-icon Vulnrichment

Updated: 2026-06-03T17:34:22.031Z

cve-icon NVD

Status : Received

Published: 2026-06-03T14:16:31.217

Modified: 2026-06-03T19:16:21.133

Link: CVE-2025-70100

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-06-03T21:00:06Z

Weaknesses