CVE-2025-38652 | Linux Kernel up to 6.1.147/6.6.101/6.12.41/6.15.9/6.16.0 f2fs path[] out-of-bounds (Nessus ID 276629 / WID-SEC-2025-1898)
A vulnerability described as critical has been identified in Linux Kernel up to 6.1.147/6.6.101/6.12.41/6.15.9/6.16.0. Affected by this issue is some unknown functionality of the component f2fs. The manipulation of the argument path[] results in out-of-bounds read.
This vulnerability is reported as CVE-2025-38652. The attacker must have access to the local network to execute the attack. No exploit exists.
Upgrading the affected component is recommended.