CVE-2025-38503
Linux Debian vulnerability analysis and mitigation

Overview

CVE-2025-38503 is a vulnerability discovered in the Linux kernel that affects the btrfs filesystem component. The vulnerability was first reported on August 16, 2025, and involves an assertion failure when building the free space tree with the block group tree feature enabled (NVD). The vulnerability affects various Linux distributions including bullseye, bookworm, trixie, and forky versions (Debian Tracker).

Technical details

The vulnerability occurs in the btrfs filesystem when building the free space tree with the block group tree feature enabled. The issue manifests as an assertion failure in fs/btrfs/free-space-tree.c:1102, which can trigger when processing an empty block group that has no allocated extents. The assertion failure occurs because the block group items are stored in a dedicated tree when using the block group tree feature, leading to incorrect handling of cases where there are no higher keys in the extent root (NVD).

Impact

When triggered, the vulnerability results in a kernel BUG and system crash, causing a denial of service condition. The issue affects systems using the btrfs filesystem with the block group tree feature enabled (NVD).

Mitigation and workarounds

The vulnerability has been fixed in certain Linux distributions, while others remain vulnerable. According to the Debian Security Tracker, the fix has been applied to bookworm and trixie releases, while bullseye, forky, and sid versions remain vulnerable (Debian Tracker).

Additional resources


SourceThis report was generated using AI

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management