CVE-2025-38580

HIGH EPSS 4.3%
Published Aug 19, 202510mo ago · Modified Jun 17, 20261w ago
7.8 CVSS 3.1
High
Find Similar
Published Aug 19, 2025 10mo ago
Last Modified Jun 17, 2026 1w ago

Description

In the Linux kernel, the following vulnerability has been resolved: ext4: fix inode use after free in ext4_end_io_rsv_work() In ext4_io_end_defer_completion(), check if io_end->list_vec is empty to avoid adding an io_end that requires no conversion to the i_rsv_conversion_list, which in turn prevents starting an unnecessary worker. An ext4_emergency_state() check is also added to avoid attempting to abort the journal in an emergency state. Additionally, ext4_put_io_end_defer() is refactored to call ext4_io_end_defer_completion() directly instead of being open-coded. This also prevents starting an unnecessary worker when EXT4_IO_END_FAILED is set but data_err=abort is not enabled. This ensures that the check in ext4_put_io_end_defer() is consistent with the check in ext4_end_bio(). Otherwise, we might add an io_end to the i_rsv_conversion_list and then call ext4_finish_bio(), after which the inode could be freed before ext4_end_io_rsv_work() is called, triggering a use-after-free issue.

CVSS Details

Base Score
7.8
Exploitability
1.8
Impact
5.9
Vector string
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Attack Vector Local
Attack Complexity Low
Privileges Required Low
User Interaction None
Scope Unchanged
Confidentiality High
Integrity High
Availability High

Threat Intelligence

EPSS Exploit Probability
4.3% percentile
Exploit & Patch Status
No Known Exploit
Patch Available

Weaknesses 1

CWE-416 Use After Free Memory Safety

Affected Products 2

VendorProductVersionRange
linuxlinux_kernel*≥6.15  –  <6.15.10
linuxlinux_kernel*≥6.16  –  <6.16.1

References 3

  • git.kernel.org https://git.kernel.org/stable/c/469c44e66e2110054949609dde095788320139d0
    Patch
  • git.kernel.org https://git.kernel.org/stable/c/ac999862b98a0f49e858e509f776be51406f1e77
    Patch
  • git.kernel.org https://git.kernel.org/stable/c/c678bdc998754589cea2e6afab9401d7d8312ac4
    Patch

Remediation

  • git.kernel.org https://git.kernel.org/stable/c/469c44e66e2110054949609dde095788320139d0
    Patch
  • git.kernel.org https://git.kernel.org/stable/c/ac999862b98a0f49e858e509f776be51406f1e77
    Patch
  • git.kernel.org https://git.kernel.org/stable/c/c678bdc998754589cea2e6afab9401d7d8312ac4
    Patch