CVE-2025-21754 | Linux Kernel up to 6.6.77/6.12.13/6.13.2/6.14-rc1 Direct IO Write btrfs_destroy_ordered_extents injection (Nessus ID 232678 / WID-SEC-2025-0453)
A vulnerability described as problematic has been identified in Linux Kernel up to 6.6.77/6.12.13/6.13.2/6.14-rc1. This impacts the function btrfs_destroy_ordered_extents of the component Direct IO Write Handler. Such manipulation leads to injection.
This vulnerability is referenced as CVE-2025-21754. The attack needs to be initiated within the local network. No exploit is available.
Upgrading the affected component is recommended.