PT-2025-29050 · Linux+6 · Linux Kernel+6
Anubis
·
Published
2025-07-10
·
Updated
2026-05-26
·
CVE-2025-38328
CVSS v3.1
5.5
Medium
| Vector | AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H |
Name of the Vulnerable Software and Affected Versions:
Linux kernel versions prior to 5.10.234-syzkaller
Description:
A flaw exists in the jffs2 file system within the Linux kernel where the result of
jffs2 prealloc raw node refs() was not adequately checked in several places. This could lead to a null pointer dereference during garbage collection or file writing operations, potentially causing system instability or denial of service. The issue was discovered through fuzzing using Syzkaller by the Linux Verification Center.Recommendations:
Linux kernel versions prior to 5.10.234-syzkaller should be updated to version 5.10.234-syzkaller or later.
Exploit
Fix
DoS
NULL Pointer Dereference
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Astra Linux
Debian
Linuxmint
Linux Kernel
Red Os
Suse
Ubuntu