Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2025-38577

20
FAUCET Score

CVE-2025-38577 is a use-after-free vulnerability in the F2FS filesystem of the Linux kernel, specifically affecting Debian and Linux kernel distributions. This flaw, identified by syzbot, can lead to a system panic. With a CVSS score of 5.5 (MEDIUM), it has a local attack vector, low attack complexity, and a high impact on availability. There is currently no evidence of active exploitation, public exploit code, or inclusion in the CISA KEV catalog, though it has garnered some community discussion and media coverage.

Impacted Technologies

VendorProductVersion(s)CPE
>= 4.8, < 5.4.297CPE matchmatch criteria
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
>= 5.5, < 5.10.241CPE matchmatch criteria
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
>= 5.11, < 5.15.190CPE matchmatch criteria
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
>= 5.16, < 6.1.148CPE matchmatch criteria
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
>= 6.2, < 6.6.102CPE matchmatch criteria
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*

CVSS Data

CVSS version used by this source: 3.1

5.5MEDIUM

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H

Attack Vector
LOCAL
Attack Complexity
LOW
Privileges Required
LOW
User Interaction
NONE
Scope
UNCHANGED
Confidentiality Impact
NONE
Integrity Impact
NONE
Availability Impact
HIGH
Exploitability Score
1.8
Impact Score
3.6
CvssVersion
3.1

Exploit Intelligence

EPSS Score
0.17%
Probability of exploitation in next 30 days
EPSS Percentile
7.0%
Percentile rank of EPSS score among Peer Group
As of 2026-07-28
Model: v2026.06.15
This CVE's current EPSS score of 0.0017 is in the 38th percentile among its peer group of 15,940 CVEs.

Social Chatter

The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.

Media Mentions

The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Patch Available

Vendor Patches (8)

microsoftpatch availablevia msrc
Product: 20412-17084Fixed in: 6.6.104.2-1
microsoftpatch availablevia msrc
Product: azl3 kernel 6.6.96.2-2 on Azure Linux 3.0Fixed in: 6.6.104.2-1
ubuntupatch availablevia ubuntu_usn
Product: linux-ibm (noble)Fixed in: 6.8.0-1044.44
ubuntupatch availablevia ubuntu_usn
Product: linux-azure-fips (noble)Fixed in: 6.8.0-1046.52+fips1
ubuntupatch availablevia ubuntu_usn
Product: linux-xilinx (noble)Fixed in: 6.8.0-1023.24
ubuntupatch availablevia ubuntu_usn
Product: linux-azure-6.8 (jammy)Fixed in: 6.8.0-1051.57~22.04.1
ubuntupatch availablevia ubuntu_usn
Product: linux-azure (noble)Fixed in: 6.8.0-1046.52
ubuntupatch availablevia ubuntu_usn
Product: linux-ibm-6.8 (jammy)Fixed in: 6.8.0-1044.44~22.04.1

Vendor Advisories (7)

ubuntuUSN-8126-1

Linux kernel (Azure) vulnerabilities

Mar 25, 2026
ubuntuUSN-8074-2

Linux kernel (Azure FIPS) vulnerabilities

Mar 4, 2026
ubuntuUSN-8074-1

Linux kernel (Azure) vulnerabilities

Mar 4, 2026
ubuntuUSN-8052-2

Linux kernel (Xilinx) vulnerabilities

Feb 24, 2026
ubuntuUSN-8028-8

Linux kernel (IBM) vulnerabilities

Feb 24, 2026
redhatCVE-2025-38577

kernel: f2fs: fix to avoid panic in f2fs_evict_inode

Aug 19, 2025
microsoft2025-Aug/CVE-2025-38577Moderate

f2fs: fix to avoid panic in f2fs_evict_inode

Aug 12, 2025

References

git.kernel.org / stable/c/15df59809c54fbd687cdf27efbd2103a937459be
Patch
git.kernel.org / stable/c/42f9ea16aea8b49febaa87950a006a1792209f38
Patch
git.kernel.org / stable/c/4732ca17c17f5062426cfa982f43593e6b81963b
Patch
git.kernel.org / stable/c/5cd99d5aa3d39086bdb53eb5c52df16e98b101a0
Patch
git.kernel.org / stable/c/880ef748e78a1eb7df2d8e11a9ef21e98bcaabe5
Patch
git.kernel.org / stable/c/9535e440fe5bc6c5ac7cfb407e53bf788b8bf8d4
Patch
git.kernel.org / stable/c/97df495d754116c8c28ac6a4112f831727bde887
Patch
git.kernel.org / stable/c/9bbfe83924946552c4c513099c0e8c83af76311a
Patch
git.kernel.org / stable/c/a509a55f8eecc8970b3980c6f06886bbff0e2f68
Patch
lists.debian.org / debian-lts-announce/2025/10/msg00007.html
Mailing ListThird Party Advisory
lists.debian.org / debian-lts-announce/2025/10/msg00008.html
Mailing ListThird Party Advisory