CVE-2025-38652
Linux Kernel vulnerability analysis and mitigation

Overview

CVE-2025-38652 is a vulnerability discovered in the Linux kernel's F2FS (Flash-Friendly File System) implementation, disclosed on August 22, 2025. The vulnerability relates to an out-of-boundary access issue in the devs.path component when handling device paths that equal MAX_PATH_LEN (NVD).

Technical details

The vulnerability occurs when a device path length equals MAX_PATH_LEN, causing sbi->devs.path[] to potentially lack a null terminator due to the path array being fully filled. This can lead to fields located after path[] being incorrectly interpreted as part of the device path, resulting in parsing errors. The issue affects the struct f2fs_dev_info structure's path handling (NVD).

Impact

The vulnerability could lead to incorrect device path parsing in the F2FS filesystem, potentially causing system instability or failures when mounting F2FS filesystems with specifically crafted path lengths. This affects various Linux distributions including Debian's bullseye, bookworm, and trixie releases (Debian Tracker).

Mitigation and workarounds

The issue has been fixed in Linux kernel version 6.16.3-1 and later releases. The fix involves adding one byte space for sbi->devs.path[] to properly store the null character of the device path string. Users are advised to upgrade to the fixed versions available in their respective distributions (Debian Tracker).

Additional resources


SourceThis report was generated using AI

Related Linux Kernel vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2025-71142N/AN/A
  • Linux KernelLinux Kernel
  • kernel-64k-debug-devel-matched
NoNoJan 14, 2026
CVE-2025-71137N/AN/A
  • Linux KernelLinux Kernel
  • linux-gcp
NoYesJan 14, 2026
CVE-2025-71135N/AN/A
  • Linux KernelLinux Kernel
  • kernel-debug-core
NoNoJan 14, 2026
CVE-2025-71134N/AN/A
  • Linux KernelLinux Kernel
  • kernel-uki-virt
NoNoJan 14, 2026
CVE-2025-71133N/AN/A
  • Linux KernelLinux Kernel
  • kernel-modules-extra
NoYesJan 14, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management