PT-2025-27749 · Linux+4 · Linux Kernel+4

Published

2025-03-25

·

Updated

2026-04-20

·

CVE-2025-38164

CVSS v3.1

5.5

Medium

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions: Linux kernel versions prior to 6.13.0-rc1
Description: A vulnerability in the Linux kernel has been resolved, which was caused by an inconsistency between SIT and SSA in the f2fs file system. This issue could lead to a crash of the file system when trying to migrate blocks in the current segment. The problem occurred because the SSA block was not up-to-date due to the last summary block data still being in the cache of the current segment. The vulnerability could be triggered by a specific test case involving the creation of a null block device, formatting it with f2fs, and then using the fallocate command to allocate a large file.
Recommendations: For Linux kernel versions prior to 6.13.0-rc1, update to a newer version that includes the fix for this issue. As a temporary workaround, consider avoiding the use of the fallocate command with large files on f2fs file systems until the issue is resolved. Additionally, restricting access to the f2fs file system or disabling the f2fs gc range() function may help minimize the risk of exploitation.

Exploit

Fix

Allocation of Resources Without Limits

Weakness Enumeration

Related Identifiers

BDU:2025-11389
CVE-2025-38164
USN-7769-1
USN-7769-2
USN-7769-3
USN-7770-1
USN-7771-1
USN-7789-1
USN-7789-2
USN-8028-1
USN-8028-2
USN-8028-3
USN-8028-4
USN-8028-5
USN-8028-6
USN-8028-7
USN-8028-8
USN-8031-1
USN-8031-2
USN-8031-3
USN-8052-1
USN-8052-2
USN-8074-1
USN-8074-2
USN-8126-1

Affected Products

Astra Linux
Linuxmint
Linux Kernel
Red Os
Ubuntu