CVE-2025-38652 Details
Description
In the Linux kernel, the following vulnerability has been resolved: f2fs: fix to avoid out-of-boundary access in devs.path - touch /mnt/f2fs/012345678901234567890123456789012345678901234567890123 - truncate -s $((1024*1024*1024)) \ /mnt/f2fs/012345678901234567890123456789012345678901234567890123 - touch /mnt/f2fs/file - truncate -s $((1024*1024*1024)) /mnt/f2fs/file - mkfs.f2fs /mnt/f2fs/012345678901234567890123456789012345678901234567890123 \ -c /mnt/f2fs/file - mount /mnt/f2fs/012345678901234567890123456789012345678901234567890123 \ /mnt/f2fs/loop [16937.192225] F2FS-fs (loop0): Mount Device [ 0]: /mnt/f2fs/012345678901234567890123456789012345678901234567890123\xff\x01, 511, 0 - 3ffff [16937.192268] F2FS-fs (loop0): Failed to find devices If device path length equals to MAX_PATH_LEN, sbi->devs.path[] may not end up w/ null character due to path array is fully filled, So accidently, fields locate after path[] may be treated as part of device path, result in parsing wrong device path. struct f2fs_dev_info { ... char path[MAX_PATH_LEN]; ... }; Let's add one byte space for sbi->devs.path[] to store null character of device path string.
A vulnerability in the Linux kernel's F2FS (Flash-Friendly File System) implementation can lead to out-of-bounds access in the device path handling. This issue arises when the device path length reaches the maximum allowed, causing the path array to become fully populated without terminating with a null character. As a result, subsequent fields may be incorrectly interpreted as part of the device path, leading to parsing errors. The vulnerability affects several versions of the Linux kernel.
Users can upgrade to the latest version of the Linux kernel, where this vulnerability has been addressed. Instructions for upgrading the Linux kernel can be found in the official Linux documentation.
Metrics
CVSS 4.0 Severity and Vector Strings:
No CVSS 4.0 data is available for this CVE.
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
No SSVC data is available for this CVE.
References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://git.kernel.org/stable/c/1b1efa5f0e878745e94a98022e8edc675a87d78e | kernel.org | Patch |
| https://git.kernel.org/stable/c/1cf1ff15f262e8baf12201b270b6a79f9d119b2d | kernel.org | Patch |
| https://git.kernel.org/stable/c/345fc8d1838f3f8be7c8ed08d86a13dedef67136 | kernel.org | Patch |
| https://git.kernel.org/stable/c/3466721f06edff834f99d9f49f23eabc6b2cb78e | kernel.org | Patch |
| https://git.kernel.org/stable/c/5661998536af52848cc4d52a377e90368196edea | kernel.org | Patch |
| https://git.kernel.org/stable/c/666b7cf6ac9aa074b8319a2b68cba7f2c30023f0 | kernel.org | Patch |
| https://git.kernel.org/stable/c/70849d33130a2cf1d6010069ed200669c8651fbd | kernel.org | Patch |
| https://git.kernel.org/stable/c/755427093e4294ac111c3f9e40d53f681a0fbdaa | kernel.org | Patch |
| https://git.kernel.org/stable/c/dc0172c74bd9edaee7bea2ebb35f3dbd37a8ae80 | kernel.org | Patch |
| https://lists.debian.org/debian-lts-announce/2025/10/msg00007.html | CVE | Third Party Advisory |
| https://lists.debian.org/debian-lts-announce/2025/10/msg00008.html | CVE | Third Party Advisory |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-125 | Out-of-bounds Read | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| linux linux kernel | >= 4.10, < 5.4.297 >= 5.5, < 5.10.241 >= 5.11, < 5.15.190 >= 5.16, < 6.1.148 >= 6.2, < 6.6.102 >= 6.7, < 6.12.42 >= 6.13, < 6.15.10 >= 6.16, < 6.16.1 |
CPE
Remediation
| |
| debian debian linux | 11.0 |
CPE
Remediation
| |
Change History
6 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jul 30, 2026 | CVE Modified | kernel.org |
| Jun 17, 2026 | CVE Modified | kernel.org |
| Jan 7, 2026 | Initial Analysis | [email protected] |
| Nov 3, 2025 | CVE Modified | CVE |
| Aug 28, 2025 | CVE Modified | kernel.org |
| Aug 22, 2025 | New CVE Received | kernel.org |