Review reviewHigh

CVE-2025-38627

Linux Linux, linux kernel

In the Linux kernel, the following vulnerability has been resolved: f2fs: compress: fix UAF of f2fs_inode_info in f2fs_free_dic The decompress_io_ctx may be released asynchronously after I/O completion. If this file is deleted immediately after read, and the kworker of processing post_read_wq has not been executed yet due to high workloads, It is possible that the inode(f2fs_inode_info) is evicted and freed before it is used f2fs_free_dic. The UAF case as below: Thread A Thread B - f2fs_decompress_end_io - f2fs_put_dic - queue_work add free_dic work to post_read_wq - do_unlink - iput - evic...

CVSS
7.8
EPSS
0.17%
6.14% percentile
CISA KEV
Not listed
Published
2025.08.23
PRIORITY ASSESSMENT

Review review

The CVSS severity warrants an early asset and exposure review.

Known exploitationNot established by KEV
Exploit probability0.17%
Technical severityCVSS 7.8

Vulnerability overview

In the Linux kernel, the following vulnerability has been resolved: f2fs: compress: fix UAF of f2fs_inode_info in f2fs_free_dic The decompress_io_ctx may be released asynchronously after I/O completion. If this file is deleted immediately after read, and the kworker of processing post_read_wq has not been executed yet due to high workloads, It is possible that the inode(f2fs_inode_info) is evicted and freed before it is used f2fs_free_dic. The UAF case as below: Thread A Thread B - f2fs_decompress_end_io - f2fs_put_dic - queue_work add free_dic work to post_read_wq - do_unlink - iput - evic...

Affected product and versions

Product
Linux Linux, linux kernel
Affected versions
>= bff139b49d9f70c1ac5384aac94554846aa834de < 74cbeeca4f16823ba58c882e1d8b836c0e39c93d, >= bff139b49d9f70c1ac5384aac94554846aa834de < 5d604d40cd3232b09cb339941ef958e49283ed0a, >= bff139b49d9f70c1ac5384aac94554846aa834de < cc81768212cdc509e5a986274db7bc24d18cde19, >= bff139b49d9f70c1ac5384aac94554846aa834de < 8fae5b6addd5f6895e03797b56e3c7b9f9cd15c9, >= bff139b49d9f70c1ac5384aac94554846aa834de < 39868685c2a94a70762bc6d77dc81d781d05bff5, >= 6.0, >= 6.0 < 6.16.1
Fixed versions
6.16.1

Recommended response sequence

Confirm exposure before applying a vendor-supported change.

Full remediation guide
  1. 1
    Identify

    Confirm that Linux Linux, linux kernel and an affected version are present.

  2. 2
    Prioritize

    Combine exploitation signals with asset exposure and business criticality.

  3. 3
    Remediate

    Follow the vendor advisory or supported update path and preserve rollback options.

  4. 4
    Verify

    Recheck the version, service health, access paths, and relevant logs.

Technical data

CVSS vector
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
CWE
CWE-416