cbcvebase.
CVE-2025-40307
published 2025-12-08

CVE-2025-40307: In the Linux kernel, the following vulnerability has been resolved: exfat: validate cluster allocation bits of the allocation bitmap syzbot created an exfat…

PriorityP338high7.8CVSS 3.1
AVLACLPRLUINSUCHIHAH
EPSS
0.13%
2.9th percentile
In the Linux kernel, the following vulnerability has been resolved: exfat: validate cluster allocation bits of the allocation bitmap syzbot created an exfat image with cluster bits not set for the allocation bitmap. exfat-fs reads and uses the allocation bitmap without checking this. The problem is that if the start cluster of the allocation bitmap is 6, cluster 6 can be allocated when creating a directory with mkdir. exfat zeros out this cluster in exfat_mkdir, which can delete existing entries. This can reallocate the allocated entries. In addition, the allocation bitmap is also zeroed out, so cluster 6 can be reallocated. This patch adds exfat_test_bitmap_range to validate that clusters used for the allocation bitmap are correctly marked as in-use.

Affected

18 ranges
VendorProductVersion rangeFixed in
debianlinux< linux 6.17.8-1 (forky)linux 6.17.8-1 (forky)
linuxlinux
linuxlinux>= 1acf1a564b6034b5af1e7fb23cb98cb3bb4f6003 < 67ce8034dc0278ddd88cad93d4218a945180dddd67ce8034dc0278ddd88cad93d4218a945180dddd
linuxlinux>= 1acf1a564b6034b5af1e7fb23cb98cb3bb4f6003 < 6bc58b4c53795ab5fe00648344aa7d9d61175f906bc58b4c53795ab5fe00648344aa7d9d61175f90
linuxlinux>= 1acf1a564b6034b5af1e7fb23cb98cb3bb4f6003 < 13c1d24803d5b0446b3f6f0fdd67e07ac1fdc7bf13c1d24803d5b0446b3f6f0fdd67e07ac1fdc7bf
linuxlinux>= 1acf1a564b6034b5af1e7fb23cb98cb3bb4f6003 < 79c1587b6cda74deb0c86fc7ba194b92958c793c79c1587b6cda74deb0c86fc7ba194b92958c793c
linuxlinux_kernel>= 0 < 6.12.63-16.12.63-1
linuxlinux_kernel>= 0 < 6.17.8-16.17.8-1
linuxlinux_kernel>= 0 < 6.8.0-106.1066.8.0-106.106
linuxlinux_kernel>= 0 < 6.17.0-14.146.17.0-14.14
linuxlinux_kernel>= 5.7.0 < 6.12.586.12.58
linuxlinux_kernel>= 6.13.0 < 6.17.86.17.8
msrcazl3_kernel_6.6.117.1-1_on_azure_linux_3.0
msrccbl2_kernel_5.15.70.1-1_on_cbl_mariner_2.0
msrccm1_kernel_5.10.144.1-1_on_cbl_mariner_1.0
ubuntulinux-aws
ubuntulinux-oracle
ubuntulinux-xilinx

CVSS provenance

nvdv3.17.8HIGHCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
osv3.2LOW
vendor_ubuntu7.8HIGH
vendor_redhat6.3MEDIUM
vendor_msrc5.5MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.