CVE-2025-38337 is a vulnerability in the Linux kernel's JBD2 journaling layer, specifically affecting the jbd2_journal_dirty_metadata() function. It involves a data race and a potential null-pointer dereference, impacting Debian and other Linux kernel distributions. The vulnerability has a CVSS score of 5.5 (Medium), indicating a local attack vector with low complexity, requiring local privileges, and potentially leading to high availability impact (denial of service) without affecting confidentiality or integrity. There is no evidence of active exploitation, public exploit code (Metasploit, Nuclei, ExploitDB), or inclusion in the CISA KEV catalog, though it has received some community and media attention.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 4.3, < 5.4.295CPE matchmatch criteria | cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* | ||
>= 5.5, < 5.10.239CPE matchmatch criteria | cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* | ||
>= 5.11, < 5.15.186CPE matchmatch criteria | cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* | ||
>= 5.16, < 6.1.142CPE matchmatch criteria | cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* | ||
>= 6.2, < 6.6.95CPE matchmatch criteria | cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Linux kernel (Azure) vulnerabilities
Mar 25, 2026Linux kernel (Azure FIPS) vulnerabilities
Mar 4, 2026Linux kernel (Azure) vulnerabilities
Mar 4, 2026Linux kernel (Xilinx) vulnerabilities
Feb 24, 2026Linux kernel (IBM) vulnerabilities
Feb 24, 2026HP ThinPro 8.1 SP9 Security Updates
Feb 2, 2026kernel: jbd2: fix data-race and null-ptr-deref in jbd2_journal_dirty_metadata()
Jul 10, 2025jbd2: fix data-race and null-ptr-deref in jbd2_journal_dirty_metadata()
Jul 8, 2025