Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

CVE-2025-38615— fs/ntfs3: cancle set bad inode after removing name fails

CVSS 7.8 · High EPSS 0.16% · P6

Possible ATT&CK Techniques 1AI

T1055 · Process Injection

Affected Version Matrix 12

VendorProductVersion RangeStatus
LinuxLinux78ab59fee07f22464f32eafebab2bd97ba94ff2d< b35a50d639ca5259466ef5fea85529bb4fb17d5baffected
78ab59fee07f22464f32eafebab2bd97ba94ff2d< 3ed2cc6a6e93fbeb8c0cafce1e7fb1f64a331dccaffected
78ab59fee07f22464f32eafebab2bd97ba94ff2d< 358d4f821c03add421a4c49290538a705852ccf1affected
78ab59fee07f22464f32eafebab2bd97ba94ff2d< a285395020780adac1ffbc844069c3d700bf007aaffected
78ab59fee07f22464f32eafebab2bd97ba94ff2d< d99208b91933fd2a58ed9ed321af07dacd06ddc3affected
5.15affected
< 5.15unaffected
6.6.102≤ 6.6.*unaffected
… +4 more rows
Get alerts for future matching vulnerabilitiesLog in to subscribe

I. Basic Information for CVE-2025-38615

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
fs/ntfs3: cancle set bad inode after removing name fails
Source: CVE Program / CVE List V5
Vulnerability Description
In the Linux kernel, the following vulnerability has been resolved: fs/ntfs3: cancle set bad inode after removing name fails The reproducer uses a file0 on a ntfs3 file system with a corrupted i_link. When renaming, the file0's inode is marked as a bad inode because the file name cannot be deleted. The underlying bug is that make_bad_inode() is called on a live inode. In some cases it's "icache lookup finds a normal inode, d_splice_alias() is called to attach it to dentry, while another thread decides to call make_bad_inode() on it - that would evict it from icache, but we'd already found it there earlier". In some it's outright "we have an inode attached to dentry - that's how we got it in the first place; let's call make_bad_inode() on it just for shits and giggles".
Source: CVE Program / CVE List V5
CVSS Information
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Source: CVE Program / CVE List V5
Vulnerability Type
N/A
Source: CVE Program / CVE List V5
Vulnerability Title
Linux kernel 安全漏洞
Source: CNNVD (China National Vulnerability Database)
Vulnerability Description
Linux kernel是美国Linux基金会的开源操作系统Linux所使用的内核。 Linux kernel存在安全漏洞,该漏洞源于错误标记活动inode为坏inode,可能导致数据损坏。
Source: CNNVD (China National Vulnerability Database)
CVSS Information
N/A
Source: CNNVD (China National Vulnerability Database)
Vulnerability Type
N/A
Source: CNNVD (China National Vulnerability Database)

Affected Products

VendorProductAffected VersionsCPESubscribe
LinuxLinux 78ab59fee07f22464f32eafebab2bd97ba94ff2d ~ b35a50d639ca5259466ef5fea85529bb4fb17d5b -
LinuxLinux 5.15 -

II. Public POCs for CVE-2025-38615

#POC DescriptionSource LinkShenlong Link
AI-Generated POCPremium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2025-38615

登录查看更多情报信息。

Same Patch Batch · Linux · 2025-08-19 · 59 CVEs total

CVE-2025-385619.8 CRITICALksmbd: fix Preauh_HashValue race condition
CVE-2025-385669.8 CRITICALsunrpc: fix handling of server side tls alerts
CVE-2025-385609.3 CRITICALx86/sev: Evict cache lines during SNP memory validation
CVE-2025-386018.8 HIGHwifi: ath11k: clear initialized flag for deinit-ed srng lists
CVE-2025-386008.8 HIGHwifi: mt76: mt7925: fix off by one in mt7925_mcu_hw_scan()
CVE-2025-385998.8 HIGHwifi: mt76: mt7996: Fix possible OOB access in mt7996_tx()
CVE-2025-385928.8 HIGHBluetooth: hci_devcd_dump: fix out-of-bounds via dev_coredumpv
CVE-2025-386088.6 HIGHbpf, ktls: Fix data corruption when using bpf_msg_pop_data() in ktls
CVE-2025-385748.6 HIGHpptp: ensure minimal skb length in pptp_xmit()
CVE-2025-385718.2 HIGHsunrpc: fix client side handling of tls alerts
CVE-2025-385827.8 HIGHRDMA/hns: Fix double destruction of rsv_qp
CVE-2025-385967.8 HIGHdrm/panthor: Fix UAF in panthor_gem_create_with_handle() debugfs code
CVE-2025-386047.8 HIGHwifi: rtl818x: Kill URBs before clearing tx status queue
CVE-2025-386077.8 HIGHbpf: handle jset (if a & b ...) as a jump in CFG computation
CVE-2025-386147.8 HIGHeventpoll: Fix semi-unbounded recursion
CVE-2025-385987.8 HIGHdrm/amdgpu: fix use-after-free in amdgpu_userq_suspend+0x51a/0x5a0
CVE-2025-385867.8 HIGHbpf, arm64: Fix fp initialization for exception boundary
CVE-2025-385957.8 HIGHxen: fix UAF in dmabuf_exp_from_pages()
CVE-2025-385807.8 HIGHext4: fix inode use after free in ext4_end_io_rsv_work()
CVE-2025-385797.8 HIGHf2fs: fix KMSAN uninit-value in extent_info usage

Showing top 20 of 59 CVEs. View all on vendor page &rarr; →

IV. Related Vulnerabilities

V. Comments for CVE-2025-38615

No comments yet


Leave a comment