
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2025-38503 is a vulnerability discovered in the Linux kernel that affects the btrfs filesystem component. The vulnerability was first reported on August 16, 2025, and involves an assertion failure when building the free space tree with the block group tree feature enabled (NVD). The vulnerability affects various Linux distributions including bullseye, bookworm, trixie, and forky versions (Debian Tracker).
The vulnerability occurs in the btrfs filesystem when building the free space tree with the block group tree feature enabled. The issue manifests as an assertion failure in fs/btrfs/free-space-tree.c:1102, which can trigger when processing an empty block group that has no allocated extents. The assertion failure occurs because the block group items are stored in a dedicated tree when using the block group tree feature, leading to incorrect handling of cases where there are no higher keys in the extent root (NVD).
When triggered, the vulnerability results in a kernel BUG and system crash, causing a denial of service condition. The issue affects systems using the btrfs filesystem with the block group tree feature enabled (NVD).
The vulnerability has been fixed in certain Linux distributions, while others remain vulnerable. According to the Debian Security Tracker, the fix has been applied to bookworm and trixie releases, while bullseye, forky, and sid versions remain vulnerable (Debian Tracker).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."