CVE Database
/

CVE-2025-38652

Back to search

CVE-2025-38652

Published: Aug 22, 2025

Modified: May 11, 2026

PUBLISHED

Description

In the Linux kernel, the following vulnerability has been resolved: f2fs: fix to avoid out-of-boundary access in devs.path - touch /mnt/f2fs/012345678901234567890123456789012345678901234567890123 - truncate -s $((1024*1024*1024)) \ /mnt/f2fs/012345678901234567890123456789012345678901234567890123 - touch /mnt/f2fs/file - truncate -s $((1024*1024*1024)) /mnt/f2fs/file - mkfs.f2fs /mnt/f2fs/012345678901234567890123456789012345678901234567890123 \ -c /mnt/f2fs/file - mount /mnt/f2fs/012345678901234567890123456789012345678901234567890123 \ /mnt/f2fs/loop [16937.192225] F2FS-fs (loop0): Mount Device [ 0]: /mnt/f2fs/012345678901234567890123456789012345678901234567890123\xff\x01, 511, 0 - 3ffff [16937.192268] F2FS-fs (loop0): Failed to find devices If device path length equals to MAX_PATH_LEN, sbi->devs.path[] may not end up w/ null character due to path array is fully filled, So accidently, fields locate after path[] may be treated as part of device path, result in parsing wrong device path. struct f2fs_dev_info { ... char path[MAX_PATH_LEN]; ... }; Let's add one byte space for sbi->devs.path[] to store null character of device path string.

VendorProductVersions

Linux

Linux

affected
3c62be17d4f562f43fe1d03b48194399caa35aa5 - < dc0172c74bd9edaee7bea2ebb35f3dbd37a8ae80
affected
3c62be17d4f562f43fe1d03b48194399caa35aa5 - < 1cf1ff15f262e8baf12201b270b6a79f9d119b2d
affected
3c62be17d4f562f43fe1d03b48194399caa35aa5 - < 666b7cf6ac9aa074b8319a2b68cba7f2c30023f0
affected
3c62be17d4f562f43fe1d03b48194399caa35aa5 - < 3466721f06edff834f99d9f49f23eabc6b2cb78e
affected
3c62be17d4f562f43fe1d03b48194399caa35aa5 - < 345fc8d1838f3f8be7c8ed08d86a13dedef67136

+4 more versions

Linux

Linux

affected
4.10
unaffected
0 - < 4.10
unaffected
5.4.297 - <= 5.4.*
unaffected
5.10.241 - <= 5.10.*
unaffected
5.15.190 - <= 5.15.*

+6 more versions

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now