CVE-2025-38206: Debian Linux
High severity, CVSS 7.8. EPSS: 0.2% chance of exploitation in the next 30 days.
In the Linux kernel, the following vulnerability has been resolved: exfat: fix double free in delayed_free The double free could happen in the following path. exfat_create_upcase_table() exfat_create_upcase_table() : return error exfat_free_upcase_table() : free ->vol_utbl exfat_load_default_upcase_table : return error exfat_kill_sb() delayed_free() exfat_free_upcase_table() <--------- double free This patch set ->vol_util as NULL after freeing it.
Affected products
- Debian Debian Linux: version 11.0 only
- Linux Linux Kernel: from 5.7, before 5.10.239 (fixed in 5.10.239); from 5.11, before 5.15.186 (fixed in 5.15.186); from 5.16, before 6.15.4 (fixed in 6.15.4)
Published 2025-07-04. Last modified 2026-09-02.