CVE-2025-70099Disclosure

LOWCVSS 7.5 · HIGH

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

A NULL pointer dereference in the ext4_dir_en_get_name_len function in include/ext4_dir.h of lwext4 1.0.0 allows attackers to cause a denial of service by supplying a specially crafted EXT4 filesystem image with malformed directory entries. During directory iteration, the code may fail to validate the directory entry pointer before accessing the name_len field, resulting in a segmentation fault. This affects versions based on (or equivalent to) the 2016-era codebase (1.0.0).

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-476

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

NONE

Momentum

NONE

Threat summary

  • 1 mentions across 1 observed day

What's happening

  • Technical details provided in 1 signal
  • Disclosure: 1 classified signal
  • 1 total mentions across 1 day

Deep dive

Activity timeline1 mentions / 1d
00111Mentions · 2026-07-01: 1Technical Details · 2026-07-01: 107-01
Signal classification1 categories
Disclosure
1100.0%
Referenced assets3 URLs
Full discourse1 post
  • Open Source Security mailing list@oss_security
    Disclosure

    lwext4: ext2/ext3/ext4 filesystem library for microcontrollers CVE-2025-70099: NULL pointer dereference https://www.openwall.com/lists/oss-security/2026/06/29/4 CVE-2025-70100: Divide-by-zero https://www.openwall.com/lists/oss-security/2026/06/29/5 CVE-2025-70101: Out-of-bounds read https://www.openwall.com/lists/oss-security/2026/06/29/6

    Post summary

    The snippet announces three newly identified vulnerabilities in the lwext4 library, mentioning their basic types and linking to Openwall advisories, without providing any proof‑of‑concept, attack tool, or patch details.

    00052573
    4.7K followersView on X

Explore more