Junglewise Threat Intelligence

CVE-2025-38578: Linux Kernel F2FS use-after-free in f2fs_sync_inode_meta

CVE-2025-38578 · Severity: high · CVSS 7.8 · Published 2025-08-19

Technologies: Linux Kernel. Vendors: Linux.

Executive brief

A vulnerability was identified in the Linux kernel's F2FS file system, which is commonly used on Android devices and flash storage. This flaw could allow a local user to cause a system crash or potentially gain unauthorized access to data by triggering a memory error during file synchronization. The issue has been resolved in recent kernel updates.

Technical details

A use-after-free (UAF) vulnerability exists in the F2FS file system within the f2fs_sync_inode_meta() function. The root cause is a race condition or improper reference counting during inode eviction and writeback, where the kernel attempts to access or delete a list entry (__list_del_entry_valid) for an inode that has already been freed. This was discovered via syzbot and KASAN. An attacker with local access could exploit this to cause a kernel panic (DoS) or execute arbitrary code in the context of the kernel. Patches have been released across multiple stable kernel branches (e.g., 6.1.y, 6.6.y, etc.).

Affected products

  • Linux Linux Kernel 6.1.129-syzkaller-00017-g642656a36791 and earlier versions

Timeline

  • 2025-07-08: patched: Initial patch authored by Chao Yu
  • 2025-08-19: disclosed: CVE published
  • 2025-08-28: advisory: Stable kernel tree commits applied

References

Related threats