
Cloud Vulnerability DB
A community-led vulnerabilities database
A null pointer dereference vulnerability was discovered in the Linux kernel's f2fs filesystem component, specifically in the f2fscheckquota_consistency() function. The vulnerability was disclosed on November 12, 2025, and is tracked as CVE-2025-40138 (NVD).
The vulnerability occurs in the f2fscheckquotaconsistency() function where a null pointer dereference can happen during the strcmp() operation. The issue manifests when comparing oldqname and new_qname without proper validation of pointer validity. This can lead to a general protection fault with a non-canonical address 0xdffffc0000000000 (NVD).
When exploited, this vulnerability results in a kernel oops (crash) due to a general protection fault, which can lead to a denial of service condition on affected systems. The issue affects systems using the F2FS filesystem with quota functionality enabled (NVD).
The vulnerability has been resolved in the Linux kernel by adding proper pointer validation before performing the strcmp() operation between oldqname and newqname in the f2fscheckquota_consistency() function (NVD).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."