CVE-2025-38615
Linux Debian vulnerability analysis and mitigation

Overview

CVE-2025-38615 is a vulnerability discovered in the Linux kernel, specifically affecting the NTFS3 filesystem component. The vulnerability was disclosed on August 19, 2025, and involves an issue where canceling the setting of a bad inode after failing to remove a filename can lead to system instability (NVD).

Technical details

The vulnerability occurs when a file on an NTFS3 filesystem has a corrupted i_link. During rename operations, the file's inode is incorrectly marked as a bad inode because the file name cannot be deleted. The core issue lies in calling make_bad_inode() on a live inode, which can lead to race conditions in the filesystem. Specifically, one scenario involves an icache lookup finding a normal inode and d_splice_alias() being called to attach it to dentry, while another thread simultaneously calls make_bad_inode() on it, causing premature eviction from icache (NVD).

Impact

When exploited, this vulnerability can cause filesystem inconsistencies and potential system instability due to improper inode handling. The issue specifically affects systems using the NTFS3 filesystem driver in the Linux kernel (NVD).

Mitigation and workarounds

Multiple patches have been released to address this vulnerability across various Linux distributions. The fix involves proper validation of inode states before calling make_bad_inode() and ensuring correct handling of the freq_table pointer (NVD).

Additional resources


SourceThis report was generated using AI

Related Linux Debian vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-22857MEDIUM6.8
  • Linux DebianLinux Debian
  • freerdp-plugins
NoNoJan 14, 2026
CVE-2026-22856MEDIUM6.8
  • Linux DebianLinux Debian
  • freerdp2
NoNoJan 14, 2026
CVE-2026-22859MEDIUM5.6
  • Linux DebianLinux Debian
  • freerdp3
NoNoJan 14, 2026
CVE-2026-22858MEDIUM5.6
  • Linux DebianLinux Debian
  • freerdp3
NoNoJan 14, 2026
CVE-2026-22036LOW3.7
  • JavaScriptJavaScript
  • node-undici
NoYesJan 14, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management