f2fs: fix KMSAN uninit-value in extent_info usage
Published Aug 19, 2025
7.8
HIGHCVSS 3.1
EPSS 0.17%
Description
KMSAN reported a use of uninitialized value in `__is_extent_mergeable()` and `__is_back_mergeable()` via the read extent tree path.
The root cause is that `get_read_extent_info()` only initializes three fields (`fofs`, `blk`, `len`) of `struct extent_info`, leaving the remaining fields uninitialized. This leads to undefined behavior when those fields are accessed later, especially during extent merging.
Fix it by zero-initializing the `extent_info` struct before population.
Affected products
-
- Version StatusaffectedConstraints
- Version StatusaffectedConstraints
- Version StatusaffectedConstraints
- Version StatusaffectedConstraints
- Version StatusaffectedConstraints
- Version StatusaffectedConstraints
- Version StatusaffectedConstraints
- Version
-
- Version 5.15StatusaffectedConstraints-
- Version 0StatusunaffectedConstraints<5.15
- Version 5.15.190StatusunaffectedConstraints<=5.15.*
- Version 6.1.148StatusunaffectedConstraints<=6.1.*
- Version 6.12.42StatusunaffectedConstraints<=6.12.*
- Version 6.15.10StatusunaffectedConstraints<=6.15.*
- Version 6.16.1StatusunaffectedConstraints<=6.16.*
- Version 6.17StatusunaffectedConstraints<=*
- Version 6.6.102StatusunaffectedConstraints<=6.6.*
- Version
Default status is the baseline for the product, each version can override it (e.g. patched versions marked unaffected).
| Vendor | Product | Default status | Versions | ||||||||||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| Linux | Linux | unaffected |
| ||||||||||||||||||||||||||||||
| Linux | Linux | affected |
|
Configuration 1
- ≥ 5.15 · < 5.15.190
- ≥ 5.16 · < 6.1.148
- ≥ 6.2 · < 6.6.102
- ≥ 6.7 · < 6.12.42
- ≥ 6.13 · < 6.15.10
- ≥ 6.16 · < 6.16.1
Configuration 2
- 11.0
No data.
Red Hat Enterprise Linux 10
kernel
Not affected
Red Hat Enterprise Linux 6
kernel
Not affected
Red Hat Enterprise Linux 7
kernel
Not affected
Red Hat Enterprise Linux 7
kernel-rt
Not affected
Red Hat Enterprise Linux 8
kernel
Not affected
Red Hat Enterprise Linux 8
kernel-rt
Not affected
Red Hat Enterprise Linux 9
kernel
Not affected
Red Hat Enterprise Linux 9
kernel-rt
Not affected
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat Enterprise Linux 10 | kernel | Not affected | n/a |
| Red Hat Enterprise Linux 6 | kernel | Not affected | n/a |
| Red Hat Enterprise Linux 7 | kernel | Not affected | n/a |
| Red Hat Enterprise Linux 7 | kernel-rt | Not affected | n/a |
| Red Hat Enterprise Linux 8 | kernel | Not affected | n/a |
| Red Hat Enterprise Linux 8 | kernel-rt | Not affected | n/a |
| Red Hat Enterprise Linux 9 | kernel | Not affected | n/a |
| Red Hat Enterprise Linux 9 | kernel-rt | Not affected | n/a |
No package ranges for this CVE.
Remediation
No remediation recorded yet.
Metrics
No CVSS v4.0 score for this CVE.
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
No CVSS v3.0 score for this CVE.
No CVSS v2.0 score for this CVE.
This CVE is not in the KEV list.
No CISA SSVC assessment for this CVE yet.
Estimated probability of exploitation in the wild in the next 30 days (FIRST EPSS). As of Oct 3, 2026.
Score over time
2025–2026- EPSS v4
- EPSS v5
Percentile over time
- EPSS v4
- EPSS v5
Table of values (3 key points)
Flat stretches are collapsed; showing up to 120 newest points.
| Date | Score | Percentile | Model |
|---|---|---|---|
| Oct 3, 2026 | 0.17% (0.00170) | 5.70th | v5 (v2026.06.15) |
| Jun 15, 2026 | 0.15% (0.00153) | 4.81th | v5 (v2026.06.15) |
| Aug 20, 2025 | 0.02% (0.00024) | 4.84th | v4 (v2025.03.14) |
References (13)
- https://access.redhat.com/security/cve/CVE-2025-38579 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=2389488 Issue Tracking
- https://git.kernel.org/stable/c/01b6f5955e0008af6bc3a181310d2744bb349800 Patch
- https://git.kernel.org/stable/c/08e8ab00a6d20d5544c932ee85a297d833895141 Patch
- https://git.kernel.org/stable/c/154467f4ad033473e5c903a03e7b9bca7df9a0fa Patch
- https://git.kernel.org/stable/c/44a79437309e0ee2276ac17aaedc71253af253a8 Patch
- https://git.kernel.org/stable/c/cc1615d5aba4f396cf412579928539a2b124c8a0 Patch
- https://git.kernel.org/stable/c/dabfa3952c8e6bfe6414dbf32e8b6c5f349dc898 Patch
- https://git.kernel.org/stable/c/e68b751ec2b15d866967812c57cfdfc1eba6a269 Patch
- https://lists.debian.org/debian-lts-announce/2025/10/msg00008.html Mailing ListThird Party Advisory
- https://lore.kernel.org/linux-cve-announce/2025081913-CVE-2025-38579-db94@gregkh/T
- https://nvd.nist.gov/vuln/detail/CVE-2025-38579
- https://www.cve.org/CVERecord?id=CVE-2025-38579
Change history (0)
No recorded changes yet.