PT-2025-33577 · Fscache+5 · Fscache+5

Published

2025-07-11

·

Updated

2025-12-15

·

CVE-2025-38534

CVSS v2.0

6.0

Medium

VectorAV:L/AC:H/Au:S/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions: Linux kernel (affected versions not specified)
Description: The netfs copy-to-cache mechanism, used by Ceph with local caching, incorrectly handles asynchronous Direct I/O (DIO) write completion notifications. Specifically, when a request is initiated to write data read to the cache, the request may hang because the application is not waiting for the notification and NETFS RREQ OFFLOAD COLLECTION is not set. This issue occurs during collection with Ceph and fscache.
Recommendations: At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Improper Resource Release

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2026-03247
CVE-2025-38534
USN-7879-1
USN-7879-2
USN-7879-3
USN-7879-4
USN-7880-1
USN-7934-1

Affected Products

Astra Linux
Ceph
Linuxmint
Linux Kernel
Ubuntu
Fscache