Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2025-38677

25
FAUCET Score

CVE-2025-38677 is an out-of-bounds access vulnerability in the F2FS file system within the Linux kernel, affecting various Debian and Linux kernel versions. This flaw occurs when a corrupted F2FS image causes the system to misinterpret a dnode as an inode, leading to an attempt to access memory beyond allocated boundaries. With a CVSS score of 7.1 (High), a local attacker with low privileges can exploit this to achieve high confidentiality impact and high availability impact. Currently, there is no evidence of active exploitation, nor are there publicly available exploit modules or proof-of-concept code.

Impacted Technologies

VendorProductVersion(s)CPE
>= 3.8, < 5.4.297CPE matchmatch criteria
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
>= 5.5, < 5.10.241CPE matchmatch criteria
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
>= 5.11, < 5.15.190CPE matchmatch criteria
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
>= 5.16, < 6.1.149CPE matchmatch criteria
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
>= 6.2, < 6.6.103CPE matchmatch criteria
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*

CVSS Data

CVSS version used by this source: 3.1

7.1HIGH

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H

Attack Vector
LOCAL
Attack Complexity
LOW
Privileges Required
LOW
User Interaction
NONE
Scope
UNCHANGED
Confidentiality Impact
HIGH
Integrity Impact
NONE
Availability Impact
HIGH
Exploitability Score
1.8
Impact Score
5.2
CvssVersion
3.1

Exploit Intelligence

EPSS Score
0.15%
Probability of exploitation in next 30 days
EPSS Percentile
4.8%
Percentile rank of EPSS score among Peer Group
As of 2026-07-27
Model: v2026.06.15
This CVE's current EPSS score of 0.0015 is in the 21st percentile among its peer group of 17,070 CVEs.

Social Chatter

The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.2 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.

Media Mentions

The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Patch Available

Vendor Patches (6)

ubuntupatch availablevia ubuntu_usn
Product: linux-xilinx (noble)Fixed in: 6.8.0-1023.24
ubuntupatch availablevia ubuntu_usn
Product: linux-ibm-6.8 (jammy)Fixed in: 6.8.0-1044.44~22.04.1
ubuntupatch availablevia ubuntu_usn
Product: linux-ibm (noble)Fixed in: 6.8.0-1044.44
ubuntupatch availablevia ubuntu_usn
Product: linux-azure-fips (noble)Fixed in: 6.8.0-1046.52+fips1
ubuntupatch availablevia ubuntu_usn
Product: linux-azure (noble)Fixed in: 6.8.0-1046.52
ubuntupatch availablevia ubuntu_usn
Product: linux-azure-6.8 (jammy)Fixed in: 6.8.0-1051.57~22.04.1

Vendor Advisories (7)

ubuntuUSN-8126-1

Linux kernel (Azure) vulnerabilities

Mar 25, 2026
ubuntuUSN-8074-2

Linux kernel (Azure FIPS) vulnerabilities

Mar 4, 2026
ubuntuUSN-8074-1

Linux kernel (Azure) vulnerabilities

Mar 4, 2026
ubuntuUSN-8052-2

Linux kernel (Xilinx) vulnerabilities

Feb 24, 2026
ubuntuUSN-8028-8

Linux kernel (IBM) vulnerabilities

Feb 24, 2026
redhatCVE-2025-38677

kernel: f2fs: fix to avoid out-of-boundary access in dnode page

Aug 30, 2025
microsoft2025-Aug/CVE-2025-38677Important

f2fs: fix to avoid out-of-boundary access in dnode page

Aug 12, 2025

References

cert-portal.siemens.com / productcert/html/ssa-032379.html
git.kernel.org / stable/c/6b7784ea07e6aa044f74b39d6b5af5e28746fc81
Patch
git.kernel.org / stable/c/77de19b6867f2740cdcb6c9c7e50d522b47847a4
Patch
git.kernel.org / stable/c/888aa660144bcb6ec07839da756ee46bfcf7fc53
Patch
git.kernel.org / stable/c/901f62efd6e855f93d8b1175540f29f4dc45ba55
Patch
git.kernel.org / stable/c/92ef491b506a0f4dd971a3a76f86f2d8f5370180
Patch
git.kernel.org / stable/c/a650654365c57407413e9b1f6ff4d539bf2e99ca
Patch
git.kernel.org / stable/c/ee4d13f5407cbdf1216cc258f45492075713889a
Patch
git.kernel.org / stable/c/f1d5093d9fe9f3c74c123741c88666cc853b79c5
Patch
lists.debian.org / debian-lts-announce/2025/10/msg00007.html
Third Party Advisory
lists.debian.org / debian-lts-announce/2025/10/msg00008.html
Third Party Advisory