Monitor vulnerabilities like this one.
Sign up free to get alerted when software you use is affected.
7.8
CVE-2025-38579: Linux Kernel: Uninitialized Data in File System Can Cause Unexpected Behavior
CVE-2025-38579
Summary
An update to the Linux kernel resolves a security issue where uninitialized data in the file system could lead to unexpected behavior, potentially causing system crashes or data corruption. This issue has been fixed, and users are advised to update their Linux kernel to the latest version. To ensure system stability, it's recommended to apply the patch as soon as possible.
What to do
No fix is available yet. Check with your software vendor for updates.
Affected software
| Vendor | Product | Affected versions |
|---|---|---|
| linux | linux_kernel |
>= 5.15, < 5.15.190 >= 5.16, < 6.1.148 >= 6.2, < 6.6.102 >= 6.7, < 6.12.42 >= 6.13, < 6.15.10 >= 6.16, < 6.16.1 cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* |
| debian | debian_linux |
11.0 cpe:2.3:o:debian:debian_linux:11.0:*:*:*:*:*:*:* |
Original title
In the Linux kernel, the following vulnerability has been resolved:
f2fs: fix KMSAN uninit-value in extent_info usage
KMSAN reported a use of uninitialized value in `__is_extent_mergeable()`
and...
Original description
In the Linux kernel, the following vulnerability has been resolved:
f2fs: fix KMSAN uninit-value in extent_info usage
KMSAN reported a use of uninitialized value in `__is_extent_mergeable()`
and `__is_back_mergeable()` via the read extent tree path.
The root cause is that `get_read_extent_info()` only initializes three
fields (`fofs`, `blk`, `len`) of `struct extent_info`, leaving the
remaining fields uninitialized. This leads to undefined behavior
when those fields are accessed later, especially during
extent merging.
Fix it by zero-initializing the `extent_info` struct before population.
f2fs: fix KMSAN uninit-value in extent_info usage
KMSAN reported a use of uninitialized value in `__is_extent_mergeable()`
and `__is_back_mergeable()` via the read extent tree path.
The root cause is that `get_read_extent_info()` only initializes three
fields (`fofs`, `blk`, `len`) of `struct extent_info`, leaving the
remaining fields uninitialized. This leads to undefined behavior
when those fields are accessed later, especially during
extent merging.
Fix it by zero-initializing the `extent_info` struct before population.
nvd CVSS3.1
7.8
Vulnerability type
CWE-908
Use of Uninitialized Resource
- https://git.kernel.org/stable/c/01b6f5955e0008af6bc3a181310d2744bb349800 Patch
- https://git.kernel.org/stable/c/08e8ab00a6d20d5544c932ee85a297d833895141 Patch
- https://git.kernel.org/stable/c/154467f4ad033473e5c903a03e7b9bca7df9a0fa Patch
- https://git.kernel.org/stable/c/44a79437309e0ee2276ac17aaedc71253af253a8 Patch
- https://git.kernel.org/stable/c/cc1615d5aba4f396cf412579928539a2b124c8a0 Patch
- https://git.kernel.org/stable/c/dabfa3952c8e6bfe6414dbf32e8b6c5f349dc898 Patch
- https://git.kernel.org/stable/c/e68b751ec2b15d866967812c57cfdfc1eba6a269 Patch
- https://lists.debian.org/debian-lts-announce/2025/10/msg00008.html Third Party Advisory Mailing List
Published: 19 Aug 2025 · Updated: 20 Jul 2026 · First seen: 7 Mar 2026