CVE-2025-38692

MEDIUM EPSS 4.1%
Published Sep 4, 202510mo ago · Modified Jun 17, 20262w ago
5.5 CVSS 3.1
Medium
Find Similar
Published Sep 4, 2025 10mo ago
Last Modified Jun 17, 2026 2w ago

Description

In the Linux kernel, the following vulnerability has been resolved: exfat: add cluster chain loop check for dir An infinite loop may occur if the following conditions occur due to file system corruption. (1) Condition for exfat_count_dir_entries() to loop infinitely. - The cluster chain includes a loop. - There is no UNUSED entry in the cluster chain. (2) Condition for exfat_create_upcase_table() to loop infinitely. - The cluster chain of the root directory includes a loop. - There are no UNUSED entry and up-case table entry in the cluster chain of the root directory. (3) Condition for exfat_load_bitmap() to loop infinitely. - The cluster chain of the root directory includes a loop. - There are no UNUSED entry and bitmap entry in the cluster chain of the root directory. (4) Condition for exfat_find_dir_entry() to loop infinitely. - The cluster chain includes a loop. - The unused directory entries were exhausted by some operation. (5) Condition for exfat_check_dir_empty() to loop infinitely. - The cluster chain includes a loop. - The unused directory entries were exhausted by some operation. - All files and sub-directories under the directory are deleted. This commit adds checks to break the above infinite loop.

CVSS Details

Base Score
5.5
Exploitability
1.8
Impact
3.6
Vector string
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
Attack Vector Local
Attack Complexity Low
Privileges Required Low
User Interaction None
Scope Unchanged
Confidentiality None
Integrity None
Availability High

Threat Intelligence

EPSS Exploit Probability
4.1% percentile
Exploit & Patch Status
No Known Exploit
Patch Available

Weaknesses 1

CWE-835

Affected Products 4

VendorProductVersionRange
linuxlinux_kernel*≥5.7  –  <6.6.103
linuxlinux_kernel*≥6.7  –  <6.12.43
linuxlinux_kernel*≥6.13  –  <6.15.11
linuxlinux_kernel*≥6.16  –  <6.16.2

References 5

  • git.kernel.org https://git.kernel.org/stable/c/4c3cda20c4cf1871e27868d08fda06b79bc7d568
    Patch
  • git.kernel.org https://git.kernel.org/stable/c/868f23286c1a13162330fa6c614fe350f78e3f82
    Patch
  • git.kernel.org https://git.kernel.org/stable/c/99f9a97dce39ad413c39b92c90393bbd6778f3fd
    Patch
  • git.kernel.org https://git.kernel.org/stable/c/aa8fe7b7b73d4c9a41bb96cb3fb3092f794ecb33
    Patch
  • git.kernel.org https://git.kernel.org/stable/c/e2066ca3ef49a30920d8536fa366b2a183a808ee
    Patch

Remediation

  • git.kernel.org https://git.kernel.org/stable/c/4c3cda20c4cf1871e27868d08fda06b79bc7d568
    Patch
  • git.kernel.org https://git.kernel.org/stable/c/868f23286c1a13162330fa6c614fe350f78e3f82
    Patch
  • git.kernel.org https://git.kernel.org/stable/c/99f9a97dce39ad413c39b92c90393bbd6778f3fd
    Patch
  • git.kernel.org https://git.kernel.org/stable/c/aa8fe7b7b73d4c9a41bb96cb3fb3092f794ecb33
    Patch
  • git.kernel.org https://git.kernel.org/stable/c/e2066ca3ef49a30920d8536fa366b2a183a808ee
    Patch