🛡️ CVE-2025-38347 — debian-linux

🟡 CVSS 5.5 — Medium ✅ No Known Exploit NVD
5.5
CVSS Score
0 Low4 Medium7 High9 Critical10

Description

f2fs: fix to do sanity check on ino and xnid

In the Linux kernel, the following vulnerability has been resolved:

f2fs: fix to do sanity check on ino and xnid

syzbot reported a f2fs bug as below:

INFO: task syz-executor140:5308 blocked for more than 143 seconds.

Not tainted 6.14.0-rc7-syzkaller-00069-g81e4f8d68c66 #0

"echo 0 > /proc/sys/kernel/hung_task_timeout_secs" disables this message.

task:syz-executor140 state:D stack:24016 pid:5308 tgid:5308 ppid:5306 task_flags:0x400140 flags:0x00000006

Call Trace:

<TASK>

context_switch kernel/sched/core.c:5378 [inline]

__schedule+0x190e/0x4c90 kernel/sched/core.c:6765

__schedule_loop kernel/sched/core.c:6842 [inline]

schedule+0x14b/0x320 kernel/sched/core.c:6857

io_schedule+0x8d/0x110 kernel/sched/core.c:7690

folio_wait_bit_common+0x839/0xee0 mm/filemap.c:1317

__folio_lock mm/filemap.c:1664 [inline]

folio_lock include/linux/pagemap.h:1163 [inline]

__filemap_get_folio+0x147/0xb40 mm/filemap.c:1917

pagecache_get_page+0x2c/0x130 mm/folio-compat.c:87

find_get_page_flags include/linux/pagemap.h:842 [inline]

f2fs_grab_cache_page+0x2b/0x320 fs/f2fs/f2fs.h:2776

__get_node_page+0x131/0x11b0 fs/f2fs/node.c:1463

read_xattr_block+0xfb/0x190 fs/f2fs/xattr.c:306

lookup_all_xattrs fs/f2fs/xattr.c:355 [inline]

f2fs_getxattr+0x676/0xf70 fs/f2fs/xattr.c:533

__f2fs_get_acl+0x52/0x870 fs/f2fs/acl.c:179

f2fs_acl_create fs/f2fs/acl.c:375 [inline]

f2fs_init_acl+0xd7/0x9b0 fs/f2fs/acl.c:418

f2fs_init_inode_metadata+0xa0f/0x1050 fs/f2fs/dir.c:539

f2fs_add_inline_entry+0x448/0x860 fs/f2fs/inline.c:666

f2fs_add_dentry+0xba/0x1e0 fs/f2fs/dir.c:765

f2fs_do_add_link+0x28c/0x3a0 fs/f2fs/dir.c:808

f2fs_add_link fs/f2fs/f2fs.h:3616 [inline]

f2fs_mknod+0x2e8/0x5b0 fs/f2fs/namei.c:766

vfs_mknod+0x36d/0x3b0 fs/namei.c:4191

unix_bind_bsd net/unix/af_unix.c:1286 [inline]

unix_bind+0x563/0xe30 net/unix/af_unix.c:1379

__sys_bind_socket net/socket.c:1817 [inline]

__sys_bind+0x1e4/0x290 net/socket.c:1848

__do_sys_bind net/socket.c:1853 [inline]

__se_sys_bind net/socket.c:1851 [inline]

__x64_sys_bind+0x7a/0x90 net/socket.c:1851

do_syscall_x64 arch/x86/entry/common.c:52 [inline]

do_syscall_64+0xf3/0x230 arch/x86/entry/common.c:83

entry_SYSCALL_64_after_hwframe+0x77/0x7f

Let's dump and check metadata of corrupted inode, it shows its xattr_nid

is the same to its i_ino.

dump.f2fs -i 3 chaseyu.img.raw

i_xattr_nid [0x 3 : 3]

So that, during mknod in the corrupted directory, it tries to get and

lock inode page twice, result in deadlock.

  • f2fs_mknod
  • f2fs_add_inline_entry
  • f2fs_get_inode_page --- lock dir's inode page
  • f2fs_init_acl
  • f2fs_acl_create(dir,..)
  • __f2fs_get_acl
  • f2fs_getxattr
  • lookup_all_xattrs
  • __get_node_page --- try to lock dir's inode page

In order to fix this, let's add sanity check on ino and xnid.

How this vulnerability can be exploited

This issue can be reached with local access to the system, attack complexity is low, an attacker needs low-level privileges on the target. No user interaction is required. The scope is unchanged, so the impact stays within the vulnerable component. Rated impact: confidentiality none, integrity none, availability high.

Affected software

CVE-2025-38347 is recorded against 3 packages.

  • debian-linux
  • kernel (from 6.13.0 up to 6.15.4)
  • linux-kernel (from 6.13 up to 6.15.4)

Timeline and source

Published on 10 July 2025 and last revised on 17 June 2026. No public exploit is currently recorded for this entry. A vendor advisory or fix has been published. Record sourced from NVD.

References

git.kernel.org
git.kernel.org
git.kernel.org
git.kernel.org
git.kernel.org
git.kernel.org
git.kernel.org
git.kernel.org
lists.debian.org
lists.debian.org
cert-portal.siemens.com

CVE-2025-38347 on other distributions

Each distribution ships its own build and its own fixed version. Pick the one you run:

Details

Severity MEDIUM
CVSS Score 5.5
CVSS Vector CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
CWE N/A
Public Exploit ✅ No
Source NVD
Published 2025-07-10
Updated 2026-08-12
Modified 2026-06-17

Affected Packages

Software From version Fixed in
debian-linux
kernel 6.13.0 6.15.4
linux-kernel 6.13 6.15.4

References

Similar Threats

Vulnerability Monitoring

Track new vulnerabilities in debian-linux

CVE-2025-38347 is rated CVSS 5.5 Medium. BotEraser monitors your WordPress installation and notifies you when software you use appears in our vulnerability database.

Set Up Free Alerts →

No credit card required  ·  Results in minutes

ⓘ Data Notice: The information presented above has been compiled from publicly available internet sources. Boteraser aggregates this data solely for informational purposes and does not independently classify, evaluate, or endorse any findings about the vulnerabilities listed. The accuracy and completeness of this information is the sole responsibility of the original publishers. Boteraser and its operators accept no liability for any decisions made based on this data.