
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2025-38692 is a denial-of-service vulnerability in the Linux kernel's exFAT file system driver caused by infinite loop conditions triggered by corrupted cluster chains. It affects Linux kernel versions from 5.7 up to (but not including) 6.6.103, 6.7 through 6.12.42, 6.13 through 6.15.10, and 6.16 through 6.16.1. The vulnerability was published on September 4, 2025, with patches released shortly after. It carries a CVSS v3.1 base score of 5.5 (Medium) (Red Hat CVE, Feedly).
The root cause is classified as CWE-835 (Loop with Unreachable Exit Condition / Infinite Loop). When an exFAT file system's cluster chain contains a circular reference due to corruption, multiple kernel functions — exfat_count_dir_entries(), exfat_create_upcase_table(), exfat_load_bitmap(), exfat_find_dir_entry(), and exfat_check_dir_empty() — can enter infinite loops if specific secondary conditions are also met (e.g., no UNUSED entries present in the chain). Exploitation requires local access with low privileges and the ability to mount or interact with a specially crafted or corrupted exFAT file system. The fix adds loop-detection checks to each affected function to break out of circular cluster chain traversal (Red Hat CVE, Kernel Patch).
Successful exploitation causes the affected kernel functions to loop indefinitely, resulting in system unresponsiveness and a denial-of-service condition. The vulnerability has no confidentiality or integrity impact — only availability is affected, with a high severity rating for that dimension. An attacker with low-privileged local access who can mount or manipulate a corrupted exFAT volume could render the system unusable, potentially requiring a reboot to recover (Red Hat CVE).
There is no public proof-of-concept exploit and no evidence of in-the-wild exploitation at this time (Feedly). The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. The EPSS score is approximately 0.018%, reflecting a very low probability of exploitation in the near term. Exploitation requires local access and the ability to present a corrupted exFAT file system to the kernel, limiting the practical attack surface.
Apply the official Linux kernel patches that introduce cluster chain loop detection in the exFAT driver. Fixed versions include 6.6.103, 6.12.43, 6.15.11, 6.16.2, and 6.17-rc1. Patches are available via the stable kernel tree (Kernel Patch, Kernel Patch). As a workaround where patching is not immediately possible, restrict unprivileged users from mounting exFAT file systems and avoid automounting untrusted external storage devices. Regularly audit file system integrity and apply kernel updates through your distribution's update mechanism.
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."