CVE-2025-38692
Linux Kernel vulnerability analysis and mitigation

Overview

CVE-2025-38692 is a vulnerability discovered in the Linux kernel's exFAT filesystem implementation, disclosed on September 4, 2025. The vulnerability affects the cluster chain loop handling in directory operations, which could lead to infinite loops under specific file system corruption conditions (NVD, Red Hat).

Technical details

The vulnerability manifests in several exFAT filesystem operations including exfatcountdirentries(), exfatcreateupcasetable(), exfatloadbitmap(), exfatfinddirentry(), and exfatcheckdirempty(). The issue occurs when the cluster chain includes a loop and specific conditions are met, such as the absence of UNUSED entries or exhaustion of directory entries. The vulnerability has been assigned a CVSS v3.1 base score of 5.5 with vector AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H (Red Hat).

Impact

The vulnerability can result in a denial of service condition through infinite loops when processing corrupted exFAT filesystems. This can affect system availability and potentially cause resource exhaustion when the filesystem attempts to process malformed directory structures (Red Hat).

Mitigation and workarounds

Red Hat has indicated that mitigation options are either not available or do not meet their Product Security criteria for ease of use, deployment, and stability. The vulnerability status is marked as 'Fix deferred' for Red Hat Enterprise Linux 9 and 10, while it is considered out of support scope for earlier versions (Red Hat).

Additional resources


SourceThis report was generated using AI

Related Linux Kernel vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2025-40258HIGH7
  • Linux KernelLinux Kernel
  • kernel-rt-64k-debug-devel-matched
NoNoDec 04, 2025
CVE-2025-40259MEDIUM6.2
  • Linux KernelLinux Kernel
  • kernel-rt-64k
NoNoDec 04, 2025
CVE-2025-40264MEDIUM5.5
  • Linux KernelLinux Kernel
  • kernel-64k-modules-extra
NoNoDec 04, 2025
CVE-2025-40254MEDIUM5.5
  • Linux KernelLinux Kernel
  • kernel-64k-devel-matched
NoNoDec 04, 2025
CVE-2025-40253MEDIUM5.5
  • Linux KernelLinux Kernel
  • kernel-64k-debug-modules-partner
NoNoDec 04, 2025

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management