Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2025-38652

23
FAUCET Score

CVE-2025-38652 is a Linux kernel vulnerability affecting the F2FS filesystem, specifically in Debian and Ubuntu distributions. It involves an out-of-bounds read in the devs.path structure, where a device path exceeding MAX_PATH_LEN can overwrite subsequent memory, leading to incorrect device path parsing. This vulnerability has a CVSS score of 7.1 (High), indicating that a local attacker with low privileges can achieve high confidentiality and availability impacts with low attack complexity. The flaw is categorized as CWE-125 (Out-of-bounds Read). Currently, there is no known active exploitation, nor are there public exploits available in Metasploit, Nuclei, or ExploitDB. Despite this, the vulnerability has garnered some community discussion and media coverage, suggesting awareness within the cybersecurity community.

Impacted Technologies

VendorProductVersion(s)CPE
>= 4.10, < 5.4.297CPE matchmatch criteria
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
>= 5.5, < 5.10.241CPE matchmatch criteria
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
>= 5.11, < 5.15.190CPE matchmatch criteria
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
>= 5.16, < 6.1.148CPE matchmatch criteria
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
>= 6.2, < 6.6.102CPE matchmatch criteria
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*

CVSS Data

CVSS version used by this source: 3.1

7.1HIGH

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H

Attack Vector
LOCAL
Attack Complexity
LOW
Privileges Required
LOW
User Interaction
NONE
Scope
UNCHANGED
Confidentiality Impact
HIGH
Integrity Impact
NONE
Availability Impact
HIGH
Exploitability Score
1.8
Impact Score
5.2
CvssVersion
3.1

Exploit Intelligence

EPSS Score
0.18%
Probability of exploitation in next 30 days
EPSS Percentile
7.3%
Percentile rank of EPSS score among Peer Group
As of 2026-07-27
Model: v2026.06.15
This CVE's current EPSS score of 0.0018 is in the 29th percentile among its peer group of 17,070 CVEs.

Social Chatter

The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.2 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.

Media Mentions

The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Patch Available

Vendor Patches (8)

microsoftpatch availablevia msrc
Product: 20412-17084Fixed in: 6.6.104.2-1
microsoftpatch availablevia msrc
Product: azl3 kernel 6.6.96.2-2 on Azure Linux 3.0Fixed in: 6.6.104.2-1
ubuntupatch availablevia ubuntu_usn
Product: linux-ibm (noble)Fixed in: 6.8.0-1044.44
ubuntupatch availablevia ubuntu_usn
Product: linux-azure-fips (noble)Fixed in: 6.8.0-1046.52+fips1
ubuntupatch availablevia ubuntu_usn
Product: linux-xilinx (noble)Fixed in: 6.8.0-1023.24
ubuntupatch availablevia ubuntu_usn
Product: linux-azure-6.8 (jammy)Fixed in: 6.8.0-1051.57~22.04.1
ubuntupatch availablevia ubuntu_usn
Product: linux-azure (noble)Fixed in: 6.8.0-1046.52
ubuntupatch availablevia ubuntu_usn
Product: linux-ibm-6.8 (jammy)Fixed in: 6.8.0-1044.44~22.04.1

Vendor Advisories (7)

ubuntuUSN-8126-1

Linux kernel (Azure) vulnerabilities

Mar 25, 2026
ubuntuUSN-8074-2

Linux kernel (Azure FIPS) vulnerabilities

Mar 4, 2026
ubuntuUSN-8074-1

Linux kernel (Azure) vulnerabilities

Mar 4, 2026
ubuntuUSN-8052-2

Linux kernel (Xilinx) vulnerabilities

Feb 24, 2026
ubuntuUSN-8028-8

Linux kernel (IBM) vulnerabilities

Feb 24, 2026
redhatCVE-2025-38652

kernel: f2fs: fix to avoid out-of-boundary access in devs.path

Aug 22, 2025
microsoft2025-Aug/CVE-2025-38652Moderate

f2fs: fix to avoid out-of-boundary access in devs.path

Aug 12, 2025

References

git.kernel.org / stable/c/1b1efa5f0e878745e94a98022e8edc675a87d78e
Patch
git.kernel.org / stable/c/1cf1ff15f262e8baf12201b270b6a79f9d119b2d
Patch
git.kernel.org / stable/c/345fc8d1838f3f8be7c8ed08d86a13dedef67136
Patch
git.kernel.org / stable/c/3466721f06edff834f99d9f49f23eabc6b2cb78e
Patch
git.kernel.org / stable/c/5661998536af52848cc4d52a377e90368196edea
Patch
git.kernel.org / stable/c/666b7cf6ac9aa074b8319a2b68cba7f2c30023f0
Patch
git.kernel.org / stable/c/70849d33130a2cf1d6010069ed200669c8651fbd
Patch
git.kernel.org / stable/c/755427093e4294ac111c3f9e40d53f681a0fbdaa
Patch
git.kernel.org / stable/c/dc0172c74bd9edaee7bea2ebb35f3dbd37a8ae80
Patch
lists.debian.org / debian-lts-announce/2025/10/msg00007.html
Third Party Advisory
lists.debian.org / debian-lts-announce/2025/10/msg00008.html
Third Party Advisory