CVE-2025-38206

Aliases:UBUNTU-CVE-2025-38206DEBIAN-CVE-2025-38206CGA-233h-jx45-fj52CGA-2fm7-5423-8mjxCGA-2vv9-pc6r-jhq4CGA-398m-r3qp-9g2cCGA-3gpj-q6h7-h8wvCGA-3v39-gx2f-8376CGA-3w42-5292-wvqqCGA-43qv-p4p3-p566CGA-464p-vc52-35qwCGA-4fwg-w4xq-vr34CGA-4x57-2fh7-h95mCGA-566f-2jh8-6m9wCGA-56rg-x4jg-3929CGA-57w5-qj3m-997fCGA-5fpx-3c79-mr6xCGA-5g2x-xq8g-gg2xCGA-5vh4-88x2-f7mfCGA-5x24-xfm4-jjggCGA-625w-x96m-p22fCGA-679h-6cjr-8r43CGA-6j7w-vfpq-7qqhCGA-6w7h-9ffm-vhjfCGA-76c4-8w3r-6jjrCGA-79cp-4h32-fhwjCGA-7x8r-76c2-mjcgCGA-7xv3-v54q-rxf3CGA-84vq-mrw2-9rw3CGA-883g-7cj8-mx5rCGA-88xq-44fp-2qg5CGA-8gf6-74hq-4xvxCGA-8gq4-crpx-jhcfCGA-93hm-wv4f-j4fcCGA-93vm-6pgp-3w98CGA-9cpp-rq6j-ffm2CGA-c9fr-gqwx-mvc7CGA-c9ww-w47m-86c6CGA-cpmm-vjhw-p779CGA-f3p2-wwv2-23fmCGA-f77h-qjpq-q787CGA-f7ch-9537-425rCGA-f9c3-mhq5-pqgvCGA-ffxm-9j8x-5hxqCGA-fv87-mgfh-29x9CGA-g2j3-9hqg-477rCGA-g3cg-g5jh-47fqCGA-g48f-rh7v-h4jhCGA-g5jv-h6xw-6xcqCGA-g6ph-v764-g6fhCGA-ghxp-pg7x-3vvjCGA-gxxr-4jrh-p327CGA-h555-j8g2-fhqjCGA-h7mf-mw3p-325xCGA-hgc7-hmxg-55xgCGA-hp7p-c974-h25jCGA-j3wv-4wp2-cf3cCGA-j6fj-hg7w-j2ccCGA-j79m-2vvh-whmpCGA-jcmq-c78f-4fg3CGA-jf4c-4v2x-m96gCGA-m265-hwj2-pghvCGA-m922-39x7-7g2rCGA-mp7c-58w8-2vmcCGA-mv6g-6779-j2w3CGA-p97m-2c7v-99x7CGA-pfv9-83gj-2647CGA-phg3-mgf9-xw4gCGA-pp6g-6cwh-hqr3CGA-pwfv-36m4-c6qfCGA-q27q-qfcp-h4j8CGA-q5r6-cq3j-frq3CGA-q657-4xhh-h6f3CGA-qf5g-f3hf-r34jCGA-qjrv-cm2v-f3wpCGA-qr8p-8qjm-q49gCGA-r73w-c27c-x7f2CGA-r848-83cq-2fqqCGA-r8jg-xm6v-xjhcCGA-rcw8-8ccc-358cCGA-rhg5-xhpr-5hxqCGA-rqgf-4j6r-5v59CGA-rwqv-gpmx-w2frCGA-v565-hxjq-wxgmCGA-vq5f-cm46-9v62CGA-w7cc-f93v-rh7vCGA-w8c2-5c3g-jq75CGA-w943-5wfj-xxjcCGA-wchx-h2jj-p75pCGA-wfg8-2vpx-3486CGA-wjxv-4rgw-ccmxCGA-wqx8-wv89-fjjfCGA-wvv8-28q8-xxx4CGA-wx85-q5gm-83crCGA-x3fm-q9f2-hgr2CGA-x57q-44gg-j4j5CGA-x972-p56c-q4f7CGA-xrq9-qc3c-mgpfCGA-xv2v-3vhr-97xq
Advisory lineage Upstream: 0 Downstream: 106
Modified
Published: 04 Jul 2025, 13:37
Last modified:02 Sept 2026, 12:49

Vulnerability Summary

Overall Risk (default)
medium
31/100
CVSS Score
7.8 HIGH
v3.1 (nvd)
EPSS Score
0.17% LOW
0% probability +0.15%
KEV
Not listed
Ransomware
No reports
Public exploits
None found
Dark Web
Not detected

Timeline

04 Jul 2025, 13:37
Published
Vulnerability first disclosed
02 Sept 2026, 12:49
Last Modified
Vulnerability information updated

Description

In the Linux kernel, the following vulnerability has been resolved: exfat: fix double free in delayed_free The double free could happen in the following path. exfat_create_upcase_table() exfat_create_upcase_table() : return error exfat_free_upcase_table() : free ->vol_utbl exfat_load_default_upcase_table : return error exfat_kill_sb() delayed_free() exfat_free_upcase_table() <--------- double free This patch set ->vol_util as NULL after freeing it.

CVSS Metrics

  • v3.1HIGHScore: 7.8CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

EPSS Trends

Current EPSS score: 0.17% Percentile: 6%

Techniques & Countermeasures

  • CWE-415Double Free

    The product calls free() twice on the same memory address.

Affected Systems

  • chainguardlinux-aws-6.12

    < 6.12.77-r0 | < 6.12.65-r2 | < 6.12.65-r0 | < 6.12.69-r0 | < 6.12.78-r0 | < 6.12.74-r1 | < 6.12.80-r0 | < 6.12.67-r0 | < 6.12.68-r1 | < 6.12.65-r1 | < 6.12.72-r0 | < 6.12.74-r0 | < 6.12.77-r1 | < 6.12.71-r0 | < 6.12.66-r0 | < 6.12.68-r0 | < 6.12.76-r0 | < 6.12.77-r2 | < 6.12.70-r0 | < 6.12.72-r1

  • chainguardlinux-azure-6.12

    < 6.12.72-r0 | < 6.12.77-r1 | < 6.12.70-r0 | < 6.12.65-r2 | < 6.12.65-r1 | < 6.12.76-r0 | < 6.12.77-r2 | < 6.12.77-r0 | < 6.12.74-r0 | < 6.12.71-r0 | < 6.12.66-r0 | < 6.12.65-r3 | < 6.12.69-r0 | < 6.12.67-r0 | < 6.12.80-r0 | < 6.12.78-r0 | < 6.12.68-r0 | < 6.12.65-r4 | < 6.12.74-r1

  • chainguardlinux-gcp-6.12

    < 6.12.78-r0 | < 6.12.65-r2 | < 6.12.69-r0 | < 6.12.68-r0 | < 6.12.70-r0 | < 6.12.72-r0 | < 6.12.77-r1 | < 6.12.77-r0 | < 6.12.80-r0 | < 6.12.74-r1 | < 6.12.65-r1 | < 6.12.67-r0 | < 6.12.74-r0 | < 6.12.77-r2 | < 6.12.76-r0 | < 6.12.66-r0 | < 6.12.68-r1 | < 6.12.71-r0

  • chainguardlinux-qemu-6.12

    < 6.12.65-r2 | < 6.12.77-r1 | < 6.12.78-r0 | < 6.12.66-r0 | < 6.12.71-r0 | < 6.12.77-r0 | < 6.12.68-r0 | < 6.12.74-r1 | < 6.12.67-r0 | < 6.12.72-r0 | < 6.12.65-r1 | < 6.12.80-r0 | < 6.12.77-r2 | < 6.12.70-r0 | < 6.12.74-r0 | < 6.12.69-r0 | < 6.12.76-r0

  • chainguardlinux-vmware-6.12

    < 6.12.66-r0 | < 6.12.68-r0 | < 6.12.71-r0 | < 6.12.77-r1 | < 6.12.78-r0 | < 6.12.68-r1 | < 6.12.67-r0 | < 6.12.77-r0 | < 6.12.74-r0 | < 6.12.77-r2 | < 6.12.69-r0 | < 6.12.65-r1 | < 6.12.74-r1 | < 6.12.76-r0 | < 6.12.65-r2 | < 6.12.80-r0 | < 6.12.70-r0 | < 6.12.72-r0

  • debianlinux

    < 5.10.244-1 | all | < 6.1.187-1 | all | < 6.16.3-1

  • ubuntulinux

    < 5.15.0-156.166 | all

  • ubuntulinux-allwinner-5.19

    all

  • ubuntulinux-aws

    < 5.15.0-1092.99 | all

  • ubuntulinux-aws-5.0

    all

  • ubuntulinux-aws-5.11

    all

  • ubuntulinux-aws-5.13

    all

  • ubuntulinux-aws-5.15

    < 5.15.0-1092.99~20.04.1

  • ubuntulinux-aws-5.19

    all

  • ubuntulinux-aws-5.3

    all

  • ubuntulinux-aws-5.8

    all

  • ubuntulinux-aws-6.14

    < 6.14.0-1015.15~24.04.1

  • ubuntulinux-aws-6.2

    all

  • ubuntulinux-aws-6.5

    all

  • ubuntulinux-aws-6.8

    all

  • ubuntulinux-aws-fips

    all | < 5.15.0-1092.99+fips1

  • ubuntulinux-azure

    all | < 5.15.0-1096.105 | all

  • ubuntulinux-azure-5.11

    all

  • ubuntulinux-azure-5.13

    all

  • ubuntulinux-azure-5.15

    < 5.15.0-1096.105~20.04.1

  • ubuntulinux-azure-5.19

    all

  • ubuntulinux-azure-5.3

    all

  • ubuntulinux-azure-5.8

    all

  • ubuntulinux-azure-6.11

    all

  • ubuntulinux-azure-6.14

    < 6.14.0-1014.14~24.04.1

  • ubuntulinux-azure-6.2

    all

  • ubuntulinux-azure-6.5

    all

  • ubuntulinux-azure-6.8

    all

  • ubuntulinux-azure-edge

    all

  • ubuntulinux-azure-fde

    all | all | all | all

  • ubuntulinux-azure-fde-5.19

    all

  • ubuntulinux-azure-fde-6.17

    all

  • ubuntulinux-azure-fde-6.2

    all

  • ubuntulinux-azure-fde-6.8

    all

  • ubuntulinux-azure-fips

    all | < 5.15.0-1096.105+fips1

  • ubuntulinux-azure-nvidia

    all

  • ubuntulinux-azure-nvidia-6.14

    < 6.14.0-1007.7

  • ubuntulinux-bluefield

    < 5.15.0-1076.78 | all

  • ubuntulinux-fips

    all | < 5.15.0-156.166+fips1

  • ubuntulinux-gcp

    all | < 5.15.0-1092.101 | all

  • ubuntulinux-gcp-5.11

    all

  • ubuntulinux-gcp-5.13

    all

  • ubuntulinux-gcp-5.15

    < 5.15.0-1092.101~20.04.1

  • ubuntulinux-gcp-5.19

    all

  • ubuntulinux-gcp-5.3

    all

Showing first 50 affected entries in server-rendered view.

References (31)