CVE-2025-38206
Vulnerability Summary
Timeline
Description
In the Linux kernel, the following vulnerability has been resolved: exfat: fix double free in delayed_free The double free could happen in the following path. exfat_create_upcase_table() exfat_create_upcase_table() : return error exfat_free_upcase_table() : free ->vol_utbl exfat_load_default_upcase_table : return error exfat_kill_sb() delayed_free() exfat_free_upcase_table() <--------- double free This patch set ->vol_util as NULL after freeing it.
CVSS Metrics
- v3.1•HIGH•Score: 7.8CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
EPSS Trends
Current EPSS score: 0.17%• Percentile: 6%
Techniques & Countermeasures
- CWE-415•Double Free
The product calls free() twice on the same memory address.
Affected Systems
- chainguard•linux-aws-6.12
< 6.12.77-r0 | < 6.12.65-r2 | < 6.12.65-r0 | < 6.12.69-r0 | < 6.12.78-r0 | < 6.12.74-r1 | < 6.12.80-r0 | < 6.12.67-r0 | < 6.12.68-r1 | < 6.12.65-r1 | < 6.12.72-r0 | < 6.12.74-r0 | < 6.12.77-r1 | < 6.12.71-r0 | < 6.12.66-r0 | < 6.12.68-r0 | < 6.12.76-r0 | < 6.12.77-r2 | < 6.12.70-r0 | < 6.12.72-r1
- chainguard•linux-azure-6.12
< 6.12.72-r0 | < 6.12.77-r1 | < 6.12.70-r0 | < 6.12.65-r2 | < 6.12.65-r1 | < 6.12.76-r0 | < 6.12.77-r2 | < 6.12.77-r0 | < 6.12.74-r0 | < 6.12.71-r0 | < 6.12.66-r0 | < 6.12.65-r3 | < 6.12.69-r0 | < 6.12.67-r0 | < 6.12.80-r0 | < 6.12.78-r0 | < 6.12.68-r0 | < 6.12.65-r4 | < 6.12.74-r1
- chainguard•linux-gcp-6.12
< 6.12.78-r0 | < 6.12.65-r2 | < 6.12.69-r0 | < 6.12.68-r0 | < 6.12.70-r0 | < 6.12.72-r0 | < 6.12.77-r1 | < 6.12.77-r0 | < 6.12.80-r0 | < 6.12.74-r1 | < 6.12.65-r1 | < 6.12.67-r0 | < 6.12.74-r0 | < 6.12.77-r2 | < 6.12.76-r0 | < 6.12.66-r0 | < 6.12.68-r1 | < 6.12.71-r0
- chainguard•linux-qemu-6.12
< 6.12.65-r2 | < 6.12.77-r1 | < 6.12.78-r0 | < 6.12.66-r0 | < 6.12.71-r0 | < 6.12.77-r0 | < 6.12.68-r0 | < 6.12.74-r1 | < 6.12.67-r0 | < 6.12.72-r0 | < 6.12.65-r1 | < 6.12.80-r0 | < 6.12.77-r2 | < 6.12.70-r0 | < 6.12.74-r0 | < 6.12.69-r0 | < 6.12.76-r0
- chainguard•linux-vmware-6.12
< 6.12.66-r0 | < 6.12.68-r0 | < 6.12.71-r0 | < 6.12.77-r1 | < 6.12.78-r0 | < 6.12.68-r1 | < 6.12.67-r0 | < 6.12.77-r0 | < 6.12.74-r0 | < 6.12.77-r2 | < 6.12.69-r0 | < 6.12.65-r1 | < 6.12.74-r1 | < 6.12.76-r0 | < 6.12.65-r2 | < 6.12.80-r0 | < 6.12.70-r0 | < 6.12.72-r0
- debian•linux
< 5.10.244-1 | all | < 6.1.187-1 | all | < 6.16.3-1
- ubuntu•linux
< 5.15.0-156.166 | all
- ubuntu•linux-allwinner-5.19
all
- ubuntu•linux-aws
< 5.15.0-1092.99 | all
- ubuntu•linux-aws-5.0
all
- ubuntu•linux-aws-5.11
all
- ubuntu•linux-aws-5.13
all
- ubuntu•linux-aws-5.15
< 5.15.0-1092.99~20.04.1
- ubuntu•linux-aws-5.19
all
- ubuntu•linux-aws-5.3
all
- ubuntu•linux-aws-5.8
all
- ubuntu•linux-aws-6.14
< 6.14.0-1015.15~24.04.1
- ubuntu•linux-aws-6.2
all
- ubuntu•linux-aws-6.5
all
- ubuntu•linux-aws-6.8
all
- ubuntu•linux-aws-fips
all | < 5.15.0-1092.99+fips1
- ubuntu•linux-azure
all | < 5.15.0-1096.105 | all
- ubuntu•linux-azure-5.11
all
- ubuntu•linux-azure-5.13
all
- ubuntu•linux-azure-5.15
< 5.15.0-1096.105~20.04.1
- ubuntu•linux-azure-5.19
all
- ubuntu•linux-azure-5.3
all
- ubuntu•linux-azure-5.8
all
- ubuntu•linux-azure-6.11
all
- ubuntu•linux-azure-6.14
< 6.14.0-1014.14~24.04.1
- ubuntu•linux-azure-6.2
all
- ubuntu•linux-azure-6.5
all
- ubuntu•linux-azure-6.8
all
- ubuntu•linux-azure-edge
all
- ubuntu•linux-azure-fde
all | all | all | all
- ubuntu•linux-azure-fde-5.19
all
- ubuntu•linux-azure-fde-6.17
all
- ubuntu•linux-azure-fde-6.2
all
- ubuntu•linux-azure-fde-6.8
all
- ubuntu•linux-azure-fips
all | < 5.15.0-1096.105+fips1
- ubuntu•linux-azure-nvidia
all
- ubuntu•linux-azure-nvidia-6.14
< 6.14.0-1007.7
- ubuntu•linux-bluefield
< 5.15.0-1076.78 | all
- ubuntu•linux-fips
all | < 5.15.0-156.166+fips1
- ubuntu•linux-gcp
all | < 5.15.0-1092.101 | all
- ubuntu•linux-gcp-5.11
all
- ubuntu•linux-gcp-5.13
all
- ubuntu•linux-gcp-5.15
< 5.15.0-1092.101~20.04.1
- ubuntu•linux-gcp-5.19
all
- ubuntu•linux-gcp-5.3
all
Showing first 50 affected entries in server-rendered view.
References (31)
- https://git.kernel.org/stable/c/13d8de1b6568dcc31a95534ced16bc0c9a67bc15
- https://git.kernel.org/stable/c/66e84439ec2af776ce749e8540f8fdd257774152
- https://git.kernel.org/stable/c/d3cef0e7a5c1aa6217c51faa9ce8ecac35d6e1fd
- https://git.kernel.org/stable/c/1f3d9724e16d62c7d42c67d6613b8512f2887c22
- https://lists.debian.org/debian-lts-announce/2025/10/msg00007.html
- https://ubuntu.com/security/CVE-2025-38206
- https://www.cve.org/CVERecord?id=CVE-2025-38206
- https://git.kernel.org/linus/1f3d9724e16d62c7d42c67d6613b8512f2887c22
- https://ubuntu.com/security/notices/USN-7774-1
- https://ubuntu.com/security/notices/USN-7774-2
- https://ubuntu.com/security/notices/USN-7774-3
- https://ubuntu.com/security/notices/USN-7775-1
- https://ubuntu.com/security/notices/USN-7776-1
- https://ubuntu.com/security/notices/USN-7775-2
- https://ubuntu.com/security/notices/USN-7775-3
- https://ubuntu.com/security/notices/USN-7774-4
- https://ubuntu.com/security/notices/USN-7774-5
- https://ubuntu.com/security/notices/USN-7833-1
- https://ubuntu.com/security/notices/USN-7834-1
- https://ubuntu.com/security/notices/USN-7833-2
- https://ubuntu.com/security/notices/USN-7833-3
- https://ubuntu.com/security/notices/USN-7833-4
- https://ubuntu.com/security/notices/USN-7856-1
- https://security-tracker.debian.org/tracker/CVE-2025-38206
- https://git.kernel.org/stable/c/ea27703eb0efbadcd45b9949526160ed90536a72
- https://git.kernel.org/stable/c/ac65f76db9b2ff3fbc9e198c0e9aaf81b111b7d0
- https://git.kernel.org/stable/c/29abaf93357f4a7d083cf399d4306999e20db31d
- https://github.com/CVEProject/cvelistV5/tree/main/cves/2025/38xxx/CVE-2025-38206.json
- https://nvd.nist.gov/vuln/detail/CVE-2025-38206
- https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git
- https://ubuntu.com/security/notices/USN-8781-1