CVE-2025-40137 describes a bug in the Linux kernel's F2FS filesystem, specifically within the f2fs_truncate() function. An error path during inode eviction could lead to a kernel bug (BUG_ON) due to a page not being properly truncated from the cache. This vulnerability affects Linux systems utilizing the F2FS filesystem. The severity is moderate, as it can lead to a kernel panic, causing a denial of service. The attack vector likely involves triggering specific F2FS operations on a corrupted or specially crafted filesystem. The complexity appears to be high, requiring specific conditions to be met for the bug to manifest. There is no indication of active exploitation, publicly available exploit code, or significant community discussion surrounding this CVE. Its EPSS score is very low, and it is not listed on the CISA KEV catalog.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
| Linux | Linux | 3.19CNA affecteddefault affected | |
| Linux | Linux | >= 92dffd01790a5219d234fc83c3ba854f4490b7f4, < 3b0c8908faa18cded84d64822882a830ab1f4d26, >= 92dffd01790a5219d234fc83c3ba854f4490b7f4, < 83a8e4efea022506a0e049e7206bdf8be9f78148, >= 92dffd01790a5219d234fc83c3ba854f4490b7f4, < 9251a9e6e871cb03c4714a18efa8f5d4a8818450, >= 92dffd01790a5219d234fc83c3ba854f4490b7f4, < a7b7ebdd7045a36454b3e388a2ecf50344fad9e6CNA affecteddefault unaffected |
CVSS data has not been published for this CVE.
Linux kernel (Xilinx) vulnerabilities
May 7, 2026Linux kernel (Azure FIPS) vulnerabilities
Apr 9, 2026Linux kernel (Raspberry Pi) vulnerabilities
Apr 1, 2026Linux kernel (Azure) vulnerabilities
Mar 25, 2026Linux kernel (Azure) vulnerabilities
Mar 25, 2026Linux kernel (AWS) vulnerabilities
Mar 23, 2026Linux kernel (Real-time) vulnerabilities
Mar 17, 2026Linux kernel (FIPS) vulnerabilities
Mar 16, 2026Linux kernel (NVIDIA) vulnerabilities
Mar 16, 2026Linux kernel vulnerabilities
Mar 16, 2026Linux kernel (Azure) vulnerabilities
Feb 24, 2026kernel: f2fs: fix to truncate first page in error path of f2fs_truncate()
Nov 12, 2025