f2fs: fix to avoid out-of-boundary access in devs.path
Published Aug 22, 2025
7.3
HIGHCVSS 3.1
EPSS 0.18%
Description
- touch /mnt/f2fs/012345678901234567890123456789012345678901234567890123 - truncate -s $((1024*1024*1024)) \ /mnt/f2fs/012345678901234567890123456789012345678901234567890123 - touch /mnt/f2fs/file - truncate -s $((1024*1024*1024)) /mnt/f2fs/file - mkfs.f2fs /mnt/f2fs/012345678901234567890123456789012345678901234567890123 \ -c /mnt/f2fs/file - mount /mnt/f2fs/012345678901234567890123456789012345678901234567890123 \ /mnt/f2fs/loop
[16937.192225] F2FS-fs (loop0): Mount Device [ 0]: /mnt/f2fs/012345678901234567890123456789012345678901234567890123\xff\x01, 511, 0 - 3ffff [16937.192268] F2FS-fs (loop0): Failed to find devices
If device path length equals to MAX_PATH_LEN, sbi->devs.path[] may not end up w/ null character due to path array is fully filled, So accidently, fields locate after path[] may be treated as part of device path, result in parsing wrong device path.
struct f2fs_dev_info { ... char path[MAX_PATH_LEN]; ... };
Let's add one byte space for sbi->devs.path[] to store null character of device path string.
Affected products
-
- Version StatusaffectedConstraints
- Version StatusaffectedConstraints
- Version StatusaffectedConstraints
- Version StatusaffectedConstraints
- Version StatusaffectedConstraints
- Version StatusaffectedConstraints
- Version StatusaffectedConstraints
- Version StatusaffectedConstraints
- Version StatusaffectedConstraints
- Version
-
- Version 4.10StatusaffectedConstraints-
- Version 0StatusunaffectedConstraints<4.10
- Version 5.10.241StatusunaffectedConstraints<=5.10.*
- Version 5.15.190StatusunaffectedConstraints<=5.15.*
- Version 5.4.297StatusunaffectedConstraints<=5.4.*
- Version 6.1.148StatusunaffectedConstraints<=6.1.*
- Version 6.12.42StatusunaffectedConstraints<=6.12.*
- Version 6.15.10StatusunaffectedConstraints<=6.15.*
- Version 6.16.1StatusunaffectedConstraints<=6.16.*
- Version 6.17StatusunaffectedConstraints<=*
- Version 6.6.102StatusunaffectedConstraints<=6.6.*
- Version
Default status is the baseline for the product, each version can override it (e.g. patched versions marked unaffected).
| Vendor | Product | Default status | Versions | ||||||||||||||||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| Linux | Linux | unaffected |
| ||||||||||||||||||||||||||||||||||||
| Linux | Linux | affected |
|
Configuration 1
- ≥ 4.10 · < 5.4.297
- ≥ 5.5 · < 5.10.241
- ≥ 5.11 · < 5.15.190
- ≥ 5.16 · < 6.1.148
- ≥ 6.2 · < 6.6.102
- ≥ 6.7 · < 6.12.42
- ≥ 6.13 · < 6.15.10
- ≥ 6.16 · < 6.16.1
Configuration 2
- 11.0
No data.
Red Hat Enterprise Linux 10
kernel
Not affected
Red Hat Enterprise Linux 6
kernel
Not affected
Red Hat Enterprise Linux 7
kernel
Not affected
Red Hat Enterprise Linux 7
kernel-rt
Not affected
Red Hat Enterprise Linux 8
kernel
Not affected
Red Hat Enterprise Linux 8
kernel-rt
Not affected
Red Hat Enterprise Linux 9
kernel
Not affected
Red Hat Enterprise Linux 9
kernel-rt
Not affected
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat Enterprise Linux 10 | kernel | Not affected | n/a |
| Red Hat Enterprise Linux 6 | kernel | Not affected | n/a |
| Red Hat Enterprise Linux 7 | kernel | Not affected | n/a |
| Red Hat Enterprise Linux 7 | kernel-rt | Not affected | n/a |
| Red Hat Enterprise Linux 8 | kernel | Not affected | n/a |
| Red Hat Enterprise Linux 8 | kernel-rt | Not affected | n/a |
| Red Hat Enterprise Linux 9 | kernel | Not affected | n/a |
| Red Hat Enterprise Linux 9 | kernel-rt | Not affected | n/a |
No package ranges for this CVE.
Remediation
No remediation recorded yet.
References (17)
- https://access.redhat.com/security/cve/CVE-2025-38652 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=2390351 Issue Tracking
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2025-25550 Advisory
- https://git.kernel.org/stable/c/1b1efa5f0e878745e94a98022e8edc675a87d78e Patch
- https://git.kernel.org/stable/c/1cf1ff15f262e8baf12201b270b6a79f9d119b2d Patch
- https://git.kernel.org/stable/c/345fc8d1838f3f8be7c8ed08d86a13dedef67136 Patch
- https://git.kernel.org/stable/c/3466721f06edff834f99d9f49f23eabc6b2cb78e Patch
- https://git.kernel.org/stable/c/5661998536af52848cc4d52a377e90368196edea Patch
- https://git.kernel.org/stable/c/666b7cf6ac9aa074b8319a2b68cba7f2c30023f0 Patch
- https://git.kernel.org/stable/c/70849d33130a2cf1d6010069ed200669c8651fbd Patch
- https://git.kernel.org/stable/c/755427093e4294ac111c3f9e40d53f681a0fbdaa Patch
- https://git.kernel.org/stable/c/dc0172c74bd9edaee7bea2ebb35f3dbd37a8ae80 Patch
- https://lists.debian.org/debian-lts-announce/2025/10/msg00007.html Third Party Advisory
- https://lists.debian.org/debian-lts-announce/2025/10/msg00008.html Third Party Advisory
- https://lore.kernel.org/linux-cve-announce/2025082237-CVE-2025-38652-1f5b@gregkh/T
- https://nvd.nist.gov/vuln/detail/CVE-2025-38652
- https://www.cve.org/CVERecord?id=CVE-2025-38652
Change history (0)
No recorded changes yet.