cbcvebase.
CVE-2025-38627
published 2025-08-22

CVE-2025-38627: In the Linux kernel, the following vulnerability has been resolved: f2fs: compress: fix UAF of f2fs_inode_info in f2fs_free_dic The decompress_io_ctx may be…

PriorityP338high7.8CVSS 3.1
AVLACLPRLUINSUCHIHAH
EPSS
0.17%
6.1th percentile
In the Linux kernel, the following vulnerability has been resolved: f2fs: compress: fix UAF of f2fs_inode_info in f2fs_free_dic The decompress_io_ctx may be released asynchronously after I/O completion. If this file is deleted immediately after read, and the kworker of processing post_read_wq has not been executed yet due to high workloads, It is possible that the inode(f2fs_inode_info) is evicted and freed before it is used f2fs_free_dic. The UAF case as below: Thread A Thread B - f2fs_decompress_end_io - f2fs_put_dic - queue_work add free_dic work to post_read_wq - do_unlink - iput - evict - call_rcu This file is deleted after read. Thread C kworker to process post_read_wq - rcu_do_batch - f2fs_free_inode - kmem_cache_free inode is freed by rcu - process_scheduled_works - f2fs_late_free_dic - f2fs_free_dic - f2fs_release_decomp_mem read (dic->inode)->i_compress_algorithm This patch store compress_algorithm and sbi in dic to avoid inode UAF. In addition, the previous solution is deprecated in [1] may cause system hang. [1] https://lore.kernel.org/all/[email protected]

Affected

16 ranges
VendorProductVersion rangeFixed in
debianlinux< linux 6.16.3-1 (forky)linux 6.16.3-1 (forky)
linuxlinux
linuxlinux>= bff139b49d9f70c1ac5384aac94554846aa834de < 74cbeeca4f16823ba58c882e1d8b836c0e39c93d74cbeeca4f16823ba58c882e1d8b836c0e39c93d
linuxlinux>= bff139b49d9f70c1ac5384aac94554846aa834de < 5d604d40cd3232b09cb339941ef958e49283ed0a5d604d40cd3232b09cb339941ef958e49283ed0a
linuxlinux>= bff139b49d9f70c1ac5384aac94554846aa834de < cc81768212cdc509e5a986274db7bc24d18cde19cc81768212cdc509e5a986274db7bc24d18cde19
linuxlinux>= bff139b49d9f70c1ac5384aac94554846aa834de < 8fae5b6addd5f6895e03797b56e3c7b9f9cd15c98fae5b6addd5f6895e03797b56e3c7b9f9cd15c9
linuxlinux>= bff139b49d9f70c1ac5384aac94554846aa834de < 39868685c2a94a70762bc6d77dc81d781d05bff539868685c2a94a70762bc6d77dc81d781d05bff5
linuxlinux_kernel>= 0 < 6.16.3-16.16.3-1
linuxlinux_kernel>= 0 < 6.8.0-106.1066.8.0-106.106
linuxlinux_kernel>= 6.0 < 6.16.16.16.1
msrcazl3_kernel_6.6.104.2-4_on_azure_linux_3.0
msrcazl3_kernel_6.6.112.1-2_on_azure_linux_3.0
msrcazl3_kernel_6.6.117.1-1_on_azure_linux_3.0
msrcazl3_kernel_6.6.96.2-1_on_azure_linux_3.0
msrcazl3_kernel_6.6.96.2-2_on_azure_linux_3.0
ubuntulinux-xilinx

CVSS provenance

nvdv3.17.8HIGHCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
osv7.8HIGH
vendor_debian7.8HIGH
vendor_redhat7.8HIGH
vendor_ubuntu7.8HIGH
vendor_msrc5.5MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.