CVE-2025-38206

Source
https://cve.org/CVERecord?id=CVE-2025-38206
Import Source
https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2025-38206.json
JSON Data
https://api.test.osv.dev/v1/vulns/CVE-2025-38206
Downstream
Related
Published
2025-07-04T13:37:25Z
Modified
2026-09-04T03:30:29Z
Severity
  • 7.8 (High) CVSS_V3 - CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H CVSS Calculator
Summary
exfat: fix double free in delayed_free
Details

In the Linux kernel, the following vulnerability has been resolved:

exfat: fix double free in delayed_free

The double free could happen in the following path.

exfat_create_upcase_table() exfat_create_upcase_table() : return error exfat_free_upcase_table() : free ->vol_utbl exfat_load_default_upcase_table : return error exfat_kill_sb() delayed_free() exfat_free_upcase_table() <--------- double free This patch set ->vol_util as NULL after freeing it.

Database specific
{
    "cna_assigner": "Linux",
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2025/38xxx/CVE-2025-38206.json"
}
References

Affected packages

Git / git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git

Affected ranges

Type
GIT
Repo
https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git
Events
Introduced
1acf1a564b6034b5af1e7fb23cb98cb3bb4f6003
Fixed
13d8de1b6568dcc31a95534ced16bc0c9a67bc15
Fixed
66e84439ec2af776ce749e8540f8fdd257774152
Fixed
ea27703eb0efbadcd45b9949526160ed90536a72
Fixed
ac65f76db9b2ff3fbc9e198c0e9aaf81b111b7d0
Fixed
29abaf93357f4a7d083cf399d4306999e20db31d
Fixed
d3cef0e7a5c1aa6217c51faa9ce8ecac35d6e1fd
Fixed
1f3d9724e16d62c7d42c67d6613b8512f2887c22

Database specific

source
"https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2025-38206.json"

Linux / Kernel

Package

Name
Kernel

Affected ranges

Type
ECOSYSTEM
Events
Introduced
5.7.0
Fixed
5.10.239
Type
ECOSYSTEM
Events
Introduced
5.11.0
Fixed
5.15.186
Type
ECOSYSTEM
Events
Introduced
5.16.0
Fixed
6.1.187
Type
ECOSYSTEM
Events
Introduced
6.2.0
Fixed
6.6.156
Type
ECOSYSTEM
Events
Introduced
6.7.0
Fixed
6.12.108
Type
ECOSYSTEM
Events
Introduced
6.13.0
Fixed
6.15.4

Database specific

source
"https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2025-38206.json"