CVE-2025-38692
Published: Sep 4, 2025
Modified: May 11, 2026
Description
In the Linux kernel, the following vulnerability has been resolved: exfat: add cluster chain loop check for dir An infinite loop may occur if the following conditions occur due to file system corruption. (1) Condition for exfat_count_dir_entries() to loop infinitely. - The cluster chain includes a loop. - There is no UNUSED entry in the cluster chain. (2) Condition for exfat_create_upcase_table() to loop infinitely. - The cluster chain of the root directory includes a loop. - There are no UNUSED entry and up-case table entry in the cluster chain of the root directory. (3) Condition for exfat_load_bitmap() to loop infinitely. - The cluster chain of the root directory includes a loop. - There are no UNUSED entry and bitmap entry in the cluster chain of the root directory. (4) Condition for exfat_find_dir_entry() to loop infinitely. - The cluster chain includes a loop. - The unused directory entries were exhausted by some operation. (5) Condition for exfat_check_dir_empty() to loop infinitely. - The cluster chain includes a loop. - The unused directory entries were exhausted by some operation. - All files and sub-directories under the directory are deleted. This commit adds checks to break the above infinite loop.
| Vendor | Product | Versions |
|---|---|---|
Linux | Linux | affected 1acf1a564b6034b5af1e7fb23cb98cb3bb4f6003 - < 868f23286c1a13162330fa6c614fe350f78e3f82affected 1acf1a564b6034b5af1e7fb23cb98cb3bb4f6003 - < aa8fe7b7b73d4c9a41bb96cb3fb3092f794ecb33affected 1acf1a564b6034b5af1e7fb23cb98cb3bb4f6003 - < e2066ca3ef49a30920d8536fa366b2a183a808eeaffected 1acf1a564b6034b5af1e7fb23cb98cb3bb4f6003 - < 4c3cda20c4cf1871e27868d08fda06b79bc7d568affected 1acf1a564b6034b5af1e7fb23cb98cb3bb4f6003 - < 99f9a97dce39ad413c39b92c90393bbd6778f3fd |
Linux | Linux | affected 5.7unaffected 0 - < 5.7unaffected 6.6.103 - <= 6.6.*unaffected 6.12.43 - <= 6.12.*unaffected 6.15.11 - <= 6.15.*+2 more versions |
References
Security Training
Train your team to recognize and prevent security threats with our comprehensive security awareness program.
Start TrainingVulnerability Scanning
Discover vulnerabilities in your applications and infrastructure before attackers do.
Scan Now