-

CVE-2025-38206

In the Linux kernel, the following vulnerability has been resolved:

exfat: fix double free in delayed_free

The double free could happen in the following path.

exfat_create_upcase_table()
        exfat_create_upcase_table() : return error
        exfat_free_upcase_table() : free ->vol_utbl
        exfat_load_default_upcase_table : return error
     exfat_kill_sb()
           delayed_free()
                  exfat_free_upcase_table() <--------- double free
This patch set ->vol_util as NULL after freeing it.

Verknüpft mit AI von unstrukturierten Daten zu bestehenden CPE der NVD
This information is available to logged-in users.
Daten sind bereitgestellt durch das CVE Programm von einer CVE Numbering Authority (CNA) (Unstrukturiert).
VendorLinux
Product Linux
Default Statusunaffected
Version < 13d8de1b6568dcc31a95534ced16bc0c9a67bc15
Version 1acf1a564b6034b5af1e7fb23cb98cb3bb4f6003
Status affected
Version < 66e84439ec2af776ce749e8540f8fdd257774152
Version 1acf1a564b6034b5af1e7fb23cb98cb3bb4f6003
Status affected
Version < d3cef0e7a5c1aa6217c51faa9ce8ecac35d6e1fd
Version 1acf1a564b6034b5af1e7fb23cb98cb3bb4f6003
Status affected
Version < 1f3d9724e16d62c7d42c67d6613b8512f2887c22
Version 1acf1a564b6034b5af1e7fb23cb98cb3bb4f6003
Status affected
VendorLinux
Product Linux
Default Statusaffected
Version 5.7
Status affected
Version < 5.7
Version 0
Status unaffected
Version <= 5.10.*
Version 5.10.239
Status unaffected
Version <= 5.15.*
Version 5.15.186
Status unaffected
Version <= 6.15.*
Version 6.15.4
Status unaffected
Version <= *
Version 6.16
Status unaffected
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Type Source Score Percentile
EPSS FIRST.org 0.03% 0.057
CVSS Metriken
Source Base Score Exploit Score Impact Score Vector string