High severity7.8NVD Advisory· Published Aug 19, 2025· Updated Jul 30, 2026
CVE-2025-38579
CVE-2025-38579
Description
In the Linux kernel, the following vulnerability has been resolved:
f2fs: fix KMSAN uninit-value in extent_info usage
KMSAN reported a use of uninitialized value in __is_extent_mergeable() and __is_back_mergeable() via the read extent tree path.
The root cause is that get_read_extent_info() only initializes three fields (fofs, blk, len) of struct extent_info, leaving the remaining fields uninitialized. This leads to undefined behavior when those fields are accessed later, especially during extent merging.
Fix it by zero-initializing the extent_info struct before population.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
5Patches
Vulnerability mechanics
References
8- git.kernel.org/stable/c/01b6f5955e0008af6bc3a181310d2744bb349800nvdPatch
- git.kernel.org/stable/c/08e8ab00a6d20d5544c932ee85a297d833895141nvdPatch
- git.kernel.org/stable/c/154467f4ad033473e5c903a03e7b9bca7df9a0fanvdPatch
- git.kernel.org/stable/c/44a79437309e0ee2276ac17aaedc71253af253a8nvdPatch
- git.kernel.org/stable/c/cc1615d5aba4f396cf412579928539a2b124c8a0nvdPatch
- git.kernel.org/stable/c/dabfa3952c8e6bfe6414dbf32e8b6c5f349dc898nvdPatch
- git.kernel.org/stable/c/e68b751ec2b15d866967812c57cfdfc1eba6a269nvdPatch
- lists.debian.org/debian-lts-announce/2025/10/msg00008.htmlnvdMailing ListThird Party Advisory
News mentions
0No linked articles in our index yet.