CVE-2025-40307 — Improper Validation of Specified Index, Position, or Offset in Input in Linux
Severity
3.2LOWOSV
No vectorEPSS
0.0%
top 90.65%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedDec 8
Latest updateApr 9
Description
In the Linux kernel, the following vulnerability has been resolved:
exfat: validate cluster allocation bits of the allocation bitmap
syzbot created an exfat image with cluster bits not set for the allocation
bitmap. exfat-fs reads and uses the allocation bitmap without checking
this. The problem is that if the start cluster of the allocation bitmap
is 6, cluster 6 can be allocated when creating a directory with mkdir.
exfat zeros out this cluster in exfat_mkdir, which can delete existing
entri…
Affected Packages8 packages
▶CVEListV5linux/linux1acf1a564b6034b5af1e7fb23cb98cb3bb4f6003 — 6bc58b4c53795ab5fe00648344aa7d9d61175f90+3