目标达成 感谢每一位支持者 — 我们达成了 100% 目标!

目标: 1000 元 · 已筹: 1336

100%

CVE-2025-38580— Linux kernel 安全漏洞

CVSS 7.8 · High EPSS 0.16% · P5

影响版本矩阵 8

厂商产品版本范围状态
LinuxLinuxce51afb8cc5e1867ea0dfdf5e92ddbe31a1fad5d< ac999862b98a0f49e858e509f776be51406f1e77affected
ce51afb8cc5e1867ea0dfdf5e92ddbe31a1fad5d< 469c44e66e2110054949609dde095788320139d0affected
ce51afb8cc5e1867ea0dfdf5e92ddbe31a1fad5d< c678bdc998754589cea2e6afab9401d7d8312ac4affected
6.15affected
< 6.15unaffected
6.15.10≤ 6.15.*unaffected
6.16.1≤ 6.16.*unaffected
6.17≤ *unaffected
获取后续新漏洞提醒登录后订阅

一、 漏洞 CVE-2025-38580 基础信息

漏洞信息

对漏洞内容有疑问?看看神龙的深度分析是否有帮助!
查看神龙十问 ↗

尽管我们使用了先进的大模型技术,但其输出仍可能包含不准确或过时的信息。神龙努力确保数据的准确性,但请您根据实际情况进行核实和判断。

Vulnerability Title
ext4: fix inode use after free in ext4_end_io_rsv_work()
来源: CVE Program / CVE List V5
Vulnerability Description
In the Linux kernel, the following vulnerability has been resolved: ext4: fix inode use after free in ext4_end_io_rsv_work() In ext4_io_end_defer_completion(), check if io_end->list_vec is empty to avoid adding an io_end that requires no conversion to the i_rsv_conversion_list, which in turn prevents starting an unnecessary worker. An ext4_emergency_state() check is also added to avoid attempting to abort the journal in an emergency state. Additionally, ext4_put_io_end_defer() is refactored to call ext4_io_end_defer_completion() directly instead of being open-coded. This also prevents starting an unnecessary worker when EXT4_IO_END_FAILED is set but data_err=abort is not enabled. This ensures that the check in ext4_put_io_end_defer() is consistent with the check in ext4_end_bio(). Otherwise, we might add an io_end to the i_rsv_conversion_list and then call ext4_finish_bio(), after which the inode could be freed before ext4_end_io_rsv_work() is called, triggering a use-after-free issue.
来源: CVE Program / CVE List V5
CVSS Information
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
来源: CVE Program / CVE List V5
Vulnerability Type
N/A
来源: CVE Program / CVE List V5
Vulnerability Title
Linux kernel 安全漏洞
来源: 中国国家信息安全漏洞库 CNNVD
Vulnerability Description
Linux kernel是美国Linux基金会的开源操作系统Linux所使用的内核。 Linux kernel存在安全漏洞,该漏洞源于ext4_end_io_rsv_work函数中存在释放后重用,可能导致崩溃。
来源: 中国国家信息安全漏洞库 CNNVD
CVSS Information
N/A
来源: 中国国家信息安全漏洞库 CNNVD
Vulnerability Type
N/A
来源: 中国国家信息安全漏洞库 CNNVD

受影响产品

厂商产品影响版本CPE订阅
LinuxLinux ce51afb8cc5e1867ea0dfdf5e92ddbe31a1fad5d ~ ac999862b98a0f49e858e509f776be51406f1e77 -
LinuxLinux 6.15 -

二、漏洞 CVE-2025-38580 的公开POC

#POC 描述源链接神龙链接
AI 生成 POC高级

未找到公开 POC。

登录以生成 AI POC

三、漏洞 CVE-2025-38580 的情报信息

登录查看更多情报信息。

同批安全公告 · Linux · 2025-08-19 · 共 59 条

CVE-2025-385619.8 CRITICALLinux kernel 安全漏洞
CVE-2025-385669.8 CRITICALLinux kernel 安全漏洞
CVE-2025-385609.3 CRITICALLinux kernel 安全漏洞
CVE-2025-386018.8 HIGHLinux kernel 安全漏洞
CVE-2025-386008.8 HIGHLinux kernel 安全漏洞
CVE-2025-385998.8 HIGHLinux kernel 安全漏洞
CVE-2025-385928.8 HIGHLinux kernel 安全漏洞
CVE-2025-386088.6 HIGHLinux kernel 安全漏洞
CVE-2025-385748.6 HIGHLinux kernel 安全漏洞
CVE-2025-385718.2 HIGHLinux kernel 安全漏洞
CVE-2025-385957.8 HIGHLinux kernel 安全漏洞
CVE-2025-385987.8 HIGHLinux kernel 安全漏洞
CVE-2025-386077.8 HIGHLinux kernel 安全漏洞
CVE-2025-386147.8 HIGHLinux kernel 安全漏洞
CVE-2025-386157.8 HIGHLinux kernel 安全漏洞
CVE-2025-386047.8 HIGHLinux kernel 安全漏洞
CVE-2025-385937.8 HIGHLinux kernel 安全漏洞
CVE-2025-385867.8 HIGHLinux kernel 安全漏洞
CVE-2025-385827.8 HIGHLinux kernel 安全漏洞
CVE-2025-385797.8 HIGHLinux kernel 安全漏洞

显示前 20 条,共 59 条。 查看全部 &rarr; →

IV. Related Vulnerabilities

V. Comments for CVE-2025-38580

暂无评论


发表评论