In the Linux kernel, the following vulnerability has been resolved:
orangefs: Do not truncate file size
'len' is used to store the result of isizeread(), so making 'len' a size_t results in truncation to 4GiB on 32-bit systems.
[
{
"signature_type": "Function",
"digest": {
"function_hash": "179907887444090268398888862584779469456",
"length": 989.0
},
"signature_version": "v1",
"deprecated": false,
"source": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git@15602508ad2f923e228b9521960b4addcd27d9c4",
"target": {
"function": "orangefs_writepage_locked",
"file": "fs/orangefs/inode.c"
},
"id": "CVE-2025-38065-257f3e80"
},
{
"signature_type": "Function",
"digest": {
"function_hash": "162914382621849339213350339185310413063",
"length": 1873.0
},
"signature_version": "v1",
"deprecated": false,
"source": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git@15602508ad2f923e228b9521960b4addcd27d9c4",
"target": {
"function": "orangefs_writepages_work",
"file": "fs/orangefs/inode.c"
},
"id": "CVE-2025-38065-5665f2b5"
},
{
"signature_type": "Line",
"digest": {
"line_hashes": [
"96291426596754478325794783607542021184",
"3497567731467343092909511658642032220",
"296164022432198132428543177833892821320",
"46290865229141348779021999581575501039",
"135755798929987517000172588943072503372",
"42285795258742251712282980198314400212",
"244118039401601424580595232116452288581",
"132173485697864348889629954949700634439",
"262510480745153792711664193298161820740",
"329192949560662370176998519192720124696",
"45048932251690172327457946554769174634"
],
"threshold": 0.9
},
"signature_version": "v1",
"deprecated": false,
"source": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git@15602508ad2f923e228b9521960b4addcd27d9c4",
"target": {
"file": "fs/orangefs/inode.c"
},
"id": "CVE-2025-38065-8ac3d7fe"
}
]