Junglewise Threat Intelligence

CVE-2025-38580: Linux Kernel EXT4 use-after-free in ext4_end_io_rsv_work

CVE-2025-38580 · Severity: high · CVSS 7.8 · Published 2025-08-19

Technologies: Linux Kernel. Vendors: Linux.

Executive brief

A vulnerability in the Linux kernel's EXT4 file system could allow a local user to cause a system crash or potentially execute unauthorized code. The issue occurs during specific file writing operations where the system incorrectly handles memory after it has been released. This could lead to data corruption or a total system failure, impacting the reliability of servers and workstations using this common file system.

Technical details

A use-after-free (UAF) vulnerability exists in the EXT4 file system within the Linux kernel, specifically in the ext4_end_io_rsv_work() function. The root cause is an inconsistency between checks in ext4_put_io_end_defer() and ext4_end_bio(), which can result in an io_end structure being added to the i_rsv_conversion_list after the associated inode has already been freed. An attacker with local access could exploit this race condition to trigger memory corruption. The fix introduces additional checks for empty list vectors and emergency states in ext4_io_end_defer_completion() to prevent unnecessary worker starts and ensures consistent refactoring of the I/O completion path. Patches are available in stable kernel updates 6.15.10 and 6.16.1.

Affected products

  • Linux Linux Kernel 6.15 to 6.15.10, 6.16 to 6.16.1

Timeline

  • 2025-07-08: other: Patch authored
  • 2025-08-19: disclosed: CVE published
  • 2025-08-15: patched: Patch committed to stable branches

References

Related threats