Action not permitted
Modal body text goes here.
Modal Title
Modal Body
EUVD-2026-347134
European Vulnerability Database identifier assigned by ENISAReserved
2026-10-02 08:12
Assigner
ENISA
Alias of
a CVE record, shown under related vulnerabilities.
This identifier carries no description, severity or references of its own:
they belong to that CVE.
{
"assigner": "ENISA",
"date_reserved": "2026-10-02T08:12:25.391358+00:00",
"id": "EUVD-2026-347134"
}
CVE-2025-38652 (GCVE-0-2025-38652)
Vulnerability from cvelistv5 – Published: 2025-08-22 16:00 – Updated: 2026-08-05 12:03
VLAI
EPSS
VEX
Title
f2fs: fix to avoid out-of-boundary access in devs.path
Summary
In the Linux kernel, the following vulnerability has been resolved:
f2fs: fix to avoid out-of-boundary access in devs.path
- touch /mnt/f2fs/012345678901234567890123456789012345678901234567890123
- truncate -s $((1024*1024*1024)) \
/mnt/f2fs/012345678901234567890123456789012345678901234567890123
- touch /mnt/f2fs/file
- truncate -s $((1024*1024*1024)) /mnt/f2fs/file
- mkfs.f2fs /mnt/f2fs/012345678901234567890123456789012345678901234567890123 \
-c /mnt/f2fs/file
- mount /mnt/f2fs/012345678901234567890123456789012345678901234567890123 \
/mnt/f2fs/loop
[16937.192225] F2FS-fs (loop0): Mount Device [ 0]: /mnt/f2fs/012345678901234567890123456789012345678901234567890123\xff\x01, 511, 0 - 3ffff
[16937.192268] F2FS-fs (loop0): Failed to find devices
If device path length equals to MAX_PATH_LEN, sbi->devs.path[] may
not end up w/ null character due to path array is fully filled, So
accidently, fields locate after path[] may be treated as part of
device path, result in parsing wrong device path.
struct f2fs_dev_info {
...
char path[MAX_PATH_LEN];
...
};
Let's add one byte space for sbi->devs.path[] to store null
character of device path string.
Severity
7.3 (High)
Assigner
References
11 references
Impacted products
2 products
| Vendor | Product | Version | |
|---|---|---|---|
| Linux | Linux |
Affected:
3c62be17d4f562f43fe1d03b48194399caa35aa5 , < dc0172c74bd9edaee7bea2ebb35f3dbd37a8ae80
(git)
Affected: 3c62be17d4f562f43fe1d03b48194399caa35aa5 , < 1cf1ff15f262e8baf12201b270b6a79f9d119b2d (git) Affected: 3c62be17d4f562f43fe1d03b48194399caa35aa5 , < 666b7cf6ac9aa074b8319a2b68cba7f2c30023f0 (git) Affected: 3c62be17d4f562f43fe1d03b48194399caa35aa5 , < 3466721f06edff834f99d9f49f23eabc6b2cb78e (git) Affected: 3c62be17d4f562f43fe1d03b48194399caa35aa5 , < 345fc8d1838f3f8be7c8ed08d86a13dedef67136 (git) Affected: 3c62be17d4f562f43fe1d03b48194399caa35aa5 , < 70849d33130a2cf1d6010069ed200669c8651fbd (git) Affected: 3c62be17d4f562f43fe1d03b48194399caa35aa5 , < 755427093e4294ac111c3f9e40d53f681a0fbdaa (git) Affected: 3c62be17d4f562f43fe1d03b48194399caa35aa5 , < 1b1efa5f0e878745e94a98022e8edc675a87d78e (git) Affected: 3c62be17d4f562f43fe1d03b48194399caa35aa5 , < 5661998536af52848cc4d52a377e90368196edea (git) |
|
| Linux | Linux |
Affected:
4.10
Unaffected: 0 , < 4.10 (semver) Unaffected: 5.4.297 , ≤ 5.4.* (semver) Unaffected: 5.10.241 , ≤ 5.10.* (semver) Unaffected: 5.15.190 , ≤ 5.15.* (semver) Unaffected: 6.1.148 , ≤ 6.1.* (semver) Unaffected: 6.6.102 , ≤ 6.6.* (semver) Unaffected: 6.12.42 , ≤ 6.12.* (semver) Unaffected: 6.15.10 , ≤ 6.15.* (semver) Unaffected: 6.16.1 , ≤ 6.16.* (semver) Unaffected: 6.17 , ≤ * (original_commit_for_fix) |
{
"containers": {
"adp": [
{
"providerMetadata": {
"dateUpdated": "2025-11-03T17:40:45.643Z",
"orgId": "af854a3a-2127-422b-91ae-364da2661108",
"shortName": "CVE"
},
"references": [
{
"url": "https://lists.debian.org/debian-lts-announce/2025/10/msg00008.html"
},
{
"url": "https://lists.debian.org/debian-lts-announce/2025/10/msg00007.html"
}
],
"title": "CVE Program Container"
}
],
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"fs/f2fs/f2fs.h"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "dc0172c74bd9edaee7bea2ebb35f3dbd37a8ae80",
"status": "affected",
"version": "3c62be17d4f562f43fe1d03b48194399caa35aa5",
"versionType": "git"
},
{
"lessThan": "1cf1ff15f262e8baf12201b270b6a79f9d119b2d",
"status": "affected",
"version": "3c62be17d4f562f43fe1d03b48194399caa35aa5",
"versionType": "git"
},
{
"lessThan": "666b7cf6ac9aa074b8319a2b68cba7f2c30023f0",
"status": "affected",
"version": "3c62be17d4f562f43fe1d03b48194399caa35aa5",
"versionType": "git"
},
{
"lessThan": "3466721f06edff834f99d9f49f23eabc6b2cb78e",
"status": "affected",
"version": "3c62be17d4f562f43fe1d03b48194399caa35aa5",
"versionType": "git"
},
{
"lessThan": "345fc8d1838f3f8be7c8ed08d86a13dedef67136",
"status": "affected",
"version": "3c62be17d4f562f43fe1d03b48194399caa35aa5",
"versionType": "git"
},
{
"lessThan": "70849d33130a2cf1d6010069ed200669c8651fbd",
"status": "affected",
"version": "3c62be17d4f562f43fe1d03b48194399caa35aa5",
"versionType": "git"
},
{
"lessThan": "755427093e4294ac111c3f9e40d53f681a0fbdaa",
"status": "affected",
"version": "3c62be17d4f562f43fe1d03b48194399caa35aa5",
"versionType": "git"
},
{
"lessThan": "1b1efa5f0e878745e94a98022e8edc675a87d78e",
"status": "affected",
"version": "3c62be17d4f562f43fe1d03b48194399caa35aa5",
"versionType": "git"
},
{
"lessThan": "5661998536af52848cc4d52a377e90368196edea",
"status": "affected",
"version": "3c62be17d4f562f43fe1d03b48194399caa35aa5",
"versionType": "git"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"fs/f2fs/f2fs.h"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "4.10"
},
{
"lessThan": "4.10",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.4.*",
"status": "unaffected",
"version": "5.4.297",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.10.*",
"status": "unaffected",
"version": "5.10.241",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.15.*",
"status": "unaffected",
"version": "5.15.190",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.1.*",
"status": "unaffected",
"version": "6.1.148",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.6.*",
"status": "unaffected",
"version": "6.6.102",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.42",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.15.*",
"status": "unaffected",
"version": "6.15.10",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.16.*",
"status": "unaffected",
"version": "6.16.1",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "6.17",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.4.297",
"versionStartIncluding": "4.10",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.10.241",
"versionStartIncluding": "4.10",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.15.190",
"versionStartIncluding": "4.10",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.1.148",
"versionStartIncluding": "4.10",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.6.102",
"versionStartIncluding": "4.10",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.42",
"versionStartIncluding": "4.10",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.15.10",
"versionStartIncluding": "4.10",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.16.1",
"versionStartIncluding": "4.10",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.17",
"versionStartIncluding": "4.10",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\nf2fs: fix to avoid out-of-boundary access in devs.path\n\n- touch /mnt/f2fs/012345678901234567890123456789012345678901234567890123\n- truncate -s $((1024*1024*1024)) \\\n /mnt/f2fs/012345678901234567890123456789012345678901234567890123\n- touch /mnt/f2fs/file\n- truncate -s $((1024*1024*1024)) /mnt/f2fs/file\n- mkfs.f2fs /mnt/f2fs/012345678901234567890123456789012345678901234567890123 \\\n -c /mnt/f2fs/file\n- mount /mnt/f2fs/012345678901234567890123456789012345678901234567890123 \\\n /mnt/f2fs/loop\n\n[16937.192225] F2FS-fs (loop0): Mount Device [ 0]: /mnt/f2fs/012345678901234567890123456789012345678901234567890123\\xff\\x01, 511, 0 - 3ffff\n[16937.192268] F2FS-fs (loop0): Failed to find devices\n\nIf device path length equals to MAX_PATH_LEN, sbi-\u003edevs.path[] may\nnot end up w/ null character due to path array is fully filled, So\naccidently, fields locate after path[] may be treated as part of\ndevice path, result in parsing wrong device path.\n\nstruct f2fs_dev_info {\n...\n\tchar path[MAX_PATH_LEN];\n...\n};\n\nLet\u0027s add one byte space for sbi-\u003edevs.path[] to store null\ncharacter of device path string."
}
],
"metrics": [
{
"cvssV3_1": {
"baseScore": 7.3,
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:L/A:H",
"version": "3.1"
},
"scenarios": [
{
"lang": "en",
"value": "AV:L - The only trigger is `mount(2)` of a crafted f2fs image whose superblock `devs[].path` is a full 64 bytes with no terminator (`get_tree_bdev` \u2192 `f2fs_fill_super` \u2192 `f2fs_scan_devices`), and the resulting disclosure is read back locally via `/proc/fs/f2fs/\u003cdev\u003e/disk_map`. No network or peer-supplied data reaches this code; between Physical (removable media) and Local, the higher-severity Local applies.\nAC:L - The attacker fully controls the on-disk `f2fs_device.path[64]` bytes and the adjacent `total_segments` value, so filling the path completely deterministically leaves `sbi-\u003edevs[i].path` unterminated on every mount \u2014 exactly as the reporter demonstrated. There is no race, no memory-layout guessing, and the trailing struct fields (`start_blk`/`end_blk`) are deterministically derived from segment counts the attacker chooses.\nPR:N - The attacker needs no account or privileges on the victim system \u2014 only delivery of a malicious f2fs image on an SD card, USB stick, or disk image that a privileged auto-mount daemon (Android vold, udisks2) or administrator later processes, which is the most severe reasonable scenario for f2fs given its role as the standard Android/removable-media filesystem.\nUI:R - f2fs does not set `FS_USERNS_MOUNT`, so mounting requires `CAP_SYS_ADMIN` in the initial user namespace; the crafted image therefore reaches the vulnerable code only when a victim inserts the media or mounts the image, and that mount action constitutes user interaction.\nS:U - The over-read, the leaked slab contents, and any resulting fault all remain within the kernel\u0027s own security authority on the host performing the mount; no VM, container, or IOMMU boundary is crossed.\nC:H - The unterminated string is read until an arbitrary in-memory NUL, so the length is determined by heap contents rather than by any bound: the over-read spills into `total_segments`/`start_blk`/`end_blk`, into `nr_blkz` and the `blkz_seq` kernel heap pointer on zoned devices, and past the end of the `kzalloc`\u0027d `f2fs_dev_info` array at its last element. Those bytes are printed verbatim into dmesg and exported through the world-readable 0444 `/proc/fs/f2fs/\u003cdev\u003e/disk_map`, so adjacent slab data and a kernel heap pointer (defeating KASLR) are disclosed to unprivileged userspace and can be re-read at will.\nI:L - The mis-parsed string is handed to `bdev_file_open_by_path()`, so f2fs can attach to and write filesystem data onto a block device whose path exceeds the 64-byte on-disk field \u2014 a target the format otherwise cannot name \u2014 corrupting that device\u0027s contents. There is no out-of-bounds write or attacker-controlled store, so the modification is limited rather than arbitrary.\nA:H - The strlen/vsnprintf walk past the end of the slab object faults hard on hardened configurations (KFENCE guard page, `panic_on_warn` with a KASAN slab-out-of-bounds report) and can read into unmapped memory at a slab-page boundary, oopsing the mounting task. Even without a fault, the mis-parsed device path aborts the mount with \"Failed to find devices\", leaving the volume \u2014 typically the device\u0027s primary Android/SD-card storage \u2014 unusable."
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-08-05T12:03:40.653Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/dc0172c74bd9edaee7bea2ebb35f3dbd37a8ae80"
},
{
"url": "https://git.kernel.org/stable/c/1cf1ff15f262e8baf12201b270b6a79f9d119b2d"
},
{
"url": "https://git.kernel.org/stable/c/666b7cf6ac9aa074b8319a2b68cba7f2c30023f0"
},
{
"url": "https://git.kernel.org/stable/c/3466721f06edff834f99d9f49f23eabc6b2cb78e"
},
{
"url": "https://git.kernel.org/stable/c/345fc8d1838f3f8be7c8ed08d86a13dedef67136"
},
{
"url": "https://git.kernel.org/stable/c/70849d33130a2cf1d6010069ed200669c8651fbd"
},
{
"url": "https://git.kernel.org/stable/c/755427093e4294ac111c3f9e40d53f681a0fbdaa"
},
{
"url": "https://git.kernel.org/stable/c/1b1efa5f0e878745e94a98022e8edc675a87d78e"
},
{
"url": "https://git.kernel.org/stable/c/5661998536af52848cc4d52a377e90368196edea"
}
],
"title": "f2fs: fix to avoid out-of-boundary access in devs.path",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2025-38652",
"datePublished": "2025-08-22T16:00:56.445Z",
"dateReserved": "2025-04-16T04:51:24.030Z",
"dateUpdated": "2026-08-05T12:03:40.653Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
Loading…
Trend slope:
-
(linear fit over daily sighting counts)
Show additional events:
Loading…
Experimental. This forecast is provided for visualization only and may change without notice. Do not use it for operational decisions.
Forecast uses a logistic model when the trend is rising, or an exponential decay model when the trend is falling. Fitted via linearized least squares.
Sightings
| Author | Source | Type | Date | Other |
|---|
Nomenclature
- Seen: The vulnerability was mentioned, discussed, or observed by the user.
- Confirmed: The vulnerability has been validated from an analyst's perspective.
- Published Proof of Concept: A public proof of concept is available for this vulnerability.
- Exploited: The vulnerability was observed as exploited by the user who reported the sighting.
- Patched: The vulnerability was observed as successfully patched by the user who reported the sighting.
- Not exploited: The vulnerability was not observed as exploited by the user who reported the sighting.
- Not confirmed: The user expressed doubt about the validity of the vulnerability.
- Not patched: The vulnerability was not observed as successfully patched by the user who reported the sighting.
Loading…
Loading…
The MITRE ATT&CK techniques below are AI-generated suggestions, inferred from the description of the
vulnerability by the CIRCL/vulnerability-attack-technique-classification-roberta-base
model, served locally by ML-Gateway.
They have not been verified by an analyst and are provided for guidance only.
The approach is described in our paper Mapping CVEs to MITRE ATT&CK Techniques: A Curated Gold-Set Classifier and the Limits of LLM-Assisted Label Expansion.
Browse all ATT&CK techniques and the vulnerabilities related to each.
The approach is described in our paper Mapping CVEs to MITRE ATT&CK Techniques: A Curated Gold-Set Classifier and the Limits of LLM-Assisted Label Expansion.
Browse all ATT&CK techniques and the vulnerabilities related to each.
Loading…
Related by attack behaviour
Vulnerabilities whose description is nearest to this one in the vector space of the CIRCL/vulnerability-attack-technique-biencoder model. This is a similarity search over the bi-encoder space (plain cosine), not a classification, and it has no measured accuracy.
Loading…
Loading…