Junglewise Threat Intelligence

CVE-2025-38677: Linux Kernel F2FS out-of-bounds access in dnode page

CVE-2025-38677 · Severity: high · CVSS 7.8 · Published 2025-08-30

Technologies: Siemens SIMATIC CN 4100, Linux Kernel. Vendors: Siemens, Linux.

Executive brief

A vulnerability in the Linux kernel's F2FS file system could allow a local attacker to cause a system crash or potentially access restricted memory. The issue is triggered when the system processes a specially crafted or corrupted disk image where internal file structures (nodes) are incorrectly identified. This can lead to the system reading data outside of intended memory boundaries, impacting the stability and security of the operating system.

Technical details

An out-of-bounds (OOB) read vulnerability exists in the Linux kernel's F2FS file system implementation within 'fs/f2fs/node.c'. The root cause is a failure to validate node IDs during 'f2fs_get_dnode_of_data()'. In a corrupted filesystem image, a direct node (dnode) may share the same ID as its parent inode. When this occurs, the kernel incorrectly parses the dnode as an inode, leading to an incorrect memory offset calculation and subsequent out-of-bounds access. An attacker with the ability to mount a crafted F2FS image or trigger writes to a corrupted F2FS volume can cause a kernel panic (DoS) or potentially leak sensitive kernel memory. The fix introduces a sanity check to ensure node IDs for direct nodes do not conflict with the inode ID.

Affected products

  • Linux Linux Kernel f2fs component; fixed in 6.1.107, 6.6.48, 6.10.7, 6.11-rc5
  • Siemens SIMATIC CN 4100 versions prior to V5.0

Timeline

  • 2025-07-17: patched: Initial patch authored by Chao Yu
  • 2025-08-30: disclosed: CVE-2025-38677 published

References

Related threats