Sign in
Sign up
Explore
Enterprise
Education
Search
Help
Terms of use
About Us
Explore
Enterprise
Education
Gitee Premium
Gitee AI
AI teammates
Sign in
Sign up
Fetch the repository succeeded.
description of repo status
Open Source
>
Other
>
Operation System
&&
Watch
Unwatch
Watching
Releases Only
Ignoring
128
Star
73
Fork
331
src-openEuler
/
kernel
Closed
Code
Issues
1197
Pull Requests
35
Wiki
Insights
Pipelines
Service
JavaDoc
PHPDoc
Quality Analysis
Jenkins for Gitee
Tencent CloudBase
Tencent Cloud Serverless
悬镜安全
Aliyun SAE
Codeblitz
SBOM
DevLens
Don’t show this again
Update failed. Please try again later!
Remove this flag
Content Risk Flag
This task is identified by
as the content contains sensitive information such as code security bugs, privacy leaks, etc., so it is only accessible to contributors of this repository.
CVE-2025-38577
Done
#ICU6GQ
CVE和安全问题
openeuler-ci-bot
owner
Opened this issue
2025-08-22 10:36
一、漏洞信息 漏洞编号:[CVE-2025-38577](https://nvd.nist.gov/vuln/detail/CVE-2025-38577) 漏洞归属组件:[kernel](https://gitee.com/src-openeuler/kernel) 漏洞归属的版本:4.19.140,4.19.194,4.19.90,5.10.0,6.1.19,6.4.0,6.6.0 CVSS V3.0分值: BaseScore:N/A None Vector:CVSS:3.0/ 漏洞简述: In the Linux kernel, the following vulnerability has been resolved:f2fs: fix to avoid panic in f2fs_evict_inodeAs syzbot [1] reported as below:R10: 0000000000000100 R11: 0000000000000206 R12: 00007ffe17473450R13: 00007f28b1c10854 R14: 000000000000dae5 R15: 00007ffe17474520 </TASK>---[ end trace 0000000000000000 ]---==================================================================BUG: KASAN: use-after-free in __list_del_entry_valid+0xa6/0x130 lib/list_debug.c:62Read of size 8 at addr ffff88812d962278 by task syz-executor/564CPU: 1 PID: 564 Comm: syz-executor Tainted: G W 6.1.129-syzkaller #0Hardware name: Google Google Compute Engine/Google Compute Engine, BIOS Google 02/12/2025Call Trace: <TASK> __dump_stack+0x21/0x24 lib/dump_stack.c:88 dump_stack_lvl+0xee/0x158 lib/dump_stack.c:106 print_address_description+0x71/0x210 mm/kasan/report.c:316 print_report+0x4a/0x60 mm/kasan/report.c:427 kasan_report+0x122/0x150 mm/kasan/report.c:531 __asan_report_load8_noabort+0x14/0x20 mm/kasan/report_generic.c:351 __list_del_entry_valid+0xa6/0x130 lib/list_debug.c:62 __list_del_entry include/linux/list.h:134 [inline] list_del_init include/linux/list.h:206 [inline] f2fs_inode_synced+0xf7/0x2e0 fs/f2fs/super.c:1531 f2fs_update_inode+0x74/0x1c40 fs/f2fs/inode.c:585 f2fs_update_inode_page+0x137/0x170 fs/f2fs/inode.c:703 f2fs_write_inode+0x4ec/0x770 fs/f2fs/inode.c:731 write_inode fs/fs-writeback.c:1460 [inline] __writeback_single_inode+0x4a0/0xab0 fs/fs-writeback.c:1677 writeback_single_inode+0x221/0x8b0 fs/fs-writeback.c:1733 sync_inode_metadata+0xb6/0x110 fs/fs-writeback.c:2789 f2fs_sync_inode_meta+0x16d/0x2a0 fs/f2fs/checkpoint.c:1159 block_operations fs/f2fs/checkpoint.c:1269 [inline] f2fs_write_checkpoint+0xca3/0x2100 fs/f2fs/checkpoint.c:1658 kill_f2fs_super+0x231/0x390 fs/f2fs/super.c:4668 deactivate_locked_super+0x98/0x100 fs/super.c:332 deactivate_super+0xaf/0xe0 fs/super.c:363 cleanup_mnt+0x45f/0x4e0 fs/namespace.c:1186 __cleanup_mnt+0x19/0x20 fs/namespace.c:1193 task_work_run+0x1c6/0x230 kernel/task_work.c:203 exit_task_work include/linux/task_work.h:39 [inline] do_exit+0x9fb/0x2410 kernel/exit.c:871 do_group_exit+0x210/0x2d0 kernel/exit.c:1021 __do_sys_exit_group kernel/exit.c:1032 [inline] __se_sys_exit_group kernel/exit.c:1030 [inline] __x64_sys_exit_group+0x3f/0x40 kernel/exit.c:1030 x64_sys_call+0x7b4/0x9a0 arch/x86/include/generated/asm/syscalls_64.h:232 do_syscall_x64 arch/x86/entry/common.c:51 [inline] do_syscall_64+0x4c/0xa0 arch/x86/entry/common.c:81 entry_SYSCALL_64_after_hwframe+0x68/0xd2RIP: 0033:0x7f28b1b8e169Code: Unable to access opcode bytes at 0x7f28b1b8e13f.RSP: 002b:00007ffe174710a8 EFLAGS: 00000246 ORIG_RAX: 00000000000000e7RAX: ffffffffffffffda RBX: 00007f28b1c10879 RCX: 00007f28b1b8e169RDX: 0000000000000000 RSI: 0000000000000000 RDI: 0000000000000001RBP: 0000000000000002 R08: 00007ffe1746ee47 R09: 00007ffe17472360R10: 0000000000000009 R11: 0000000000000246 R12: 00007ffe17472360R13: 00007f28b1c10854 R14: 000000000000dae5 R15: 00007ffe17474520 </TASK>Allocated by task 569: kasan_save_stack mm/kasan/common.c:45 [inline] kasan_set_track+0x4b/0x70 mm/kasan/common.c:52 kasan_save_alloc_info+0x25/0x30 mm/kasan/generic.c:505 __kasan_slab_alloc+0x72/0x80 mm/kasan/common.c:328 kasan_slab_alloc include/linux/kasan.h:201 [inline] slab_post_alloc_hook+0x4f/0x2c0 mm/slab.h:737 slab_alloc_node mm/slub.c:3398 [inline] slab_alloc mm/slub.c:3406 [inline] __kmem_cache_alloc_lru mm/slub.c:3413 [inline] kmem_cache_alloc_lru+0x104/0x220 mm/slub.c:3429 alloc_inode_sb include/linux/fs.h:3245 [inline] f2fs_alloc_inode+0x2d/0x340 fs/f2fs/super.c:1419 alloc_inode fs/inode.c:261 [inline] iget_locked+0x186/0x880 fs/inode.c:1373 f2fs_iget+0x55/0x4c60 fs/f2fs/inode.c:483 f2fs_lookup+0x366/0xab0 fs/f2fs/namei.c:487 __lookup_slow+0x2a3/0x3d0 fs/namei.c:1690 lookup_slow+0x57/0x70 fs/namei.c:1707 walk_component+0x2e6/0x410 fs/namei---truncated--- 漏洞公开时间:2025-08-20 01:15:34 漏洞创建时间:2025-08-22 10:36:15 漏洞详情参考链接: https://nvd.nist.gov/vuln/detail/CVE-2025-38577 <details> <summary>更多参考(点击展开)</summary> | 参考来源 | 参考链接 | 来源链接 | | ------- | -------- | -------- | | | https://git.kernel.org/stable/c/42f9ea16aea8b49febaa87950a006a1792209f38 | | | | https://git.kernel.org/stable/c/4732ca17c17f5062426cfa982f43593e6b81963b | | | | https://git.kernel.org/stable/c/880ef748e78a1eb7df2d8e11a9ef21e98bcaabe5 | | | | https://git.kernel.org/stable/c/97df495d754116c8c28ac6a4112f831727bde887 | | | | https://git.kernel.org/stable/c/9bbfe83924946552c4c513099c0e8c83af76311a | | | | https://git.kernel.org/stable/c/a509a55f8eecc8970b3980c6f06886bbff0e2f68 | | | | https://security-tracker.debian.org/tracker/CVE-2025-38577 | | | | https://lore.kernel.org/linux-cve-announce/2025081912-CVE-2025-38577-f225@gregkh/T/#u | | | | https://git.kernel.org/stable/c/42f9ea16aea8b49febaa87950a006a1792209f38 | | | | https://git.kernel.org/stable/c/4732ca17c17f5062426cfa982f43593e6b81963b | | | | https://git.kernel.org/stable/c/880ef748e78a1eb7df2d8e11a9ef21e98bcaabe5 | | | | https://git.kernel.org/stable/c/97df495d754116c8c28ac6a4112f831727bde887 | | | | https://git.kernel.org/stable/c/9bbfe83924946552c4c513099c0e8c83af76311a | | | | https://git.kernel.org/stable/c/a509a55f8eecc8970b3980c6f06886bbff0e2f68 | | | | https://www.cve.org/CVERecord?id=CVE-2025-38577 | | | | https://lore.kernel.org/linux-cve-announce/2025081912-CVE-2025-38577-f225@gregkh/T | | | | https://bugzilla.redhat.com/show_bug.cgi?id=2389500 | | | | https://ubuntu.com/security/CVE-2025-38577 | | | | https://www.cve.org/CVERecord?id=CVE-2025-38577 | | | | https://git.kernel.org/linus/a509a55f8eecc8970b3980c6f06886bbff0e2f68 | | | | https://git.kernel.org/stable/c/42f9ea16aea8b49febaa87950a006a1792209f38 | | | | https://git.kernel.org/stable/c/4732ca17c17f5062426cfa982f43593e6b81963b | | | | https://git.kernel.org/stable/c/880ef748e78a1eb7df2d8e11a9ef21e98bcaabe5 | | | | https://git.kernel.org/stable/c/97df495d754116c8c28ac6a4112f831727bde887 | | | | https://git.kernel.org/stable/c/9bbfe83924946552c4c513099c0e8c83af76311a | | | | https://git.kernel.org/stable/c/a509a55f8eecc8970b3980c6f06886bbff0e2f68 | | | | https://docs.bell-sw.com/security/cves/CVE-2025-38577 | | | | https://nvd.nist.gov/vuln/detail/CVE-2025-38577 | | | | https://git.kernel.org/stable/c/15df59809c54fbd687cdf27efbd2103a937459be | | | | https://git.kernel.org/stable/c/5cd99d5aa3d39086bdb53eb5c52df16e98b101a0 | | | | https://git.kernel.org/stable/c/9535e440fe5bc6c5ac7cfb407e53bf788b8bf8d4 | | | | https://git.kernel.org/stable/c/15df59809c54fbd687cdf27efbd2103a937459be | | | | https://git.kernel.org/stable/c/9535e440fe5bc6c5ac7cfb407e53bf788b8bf8d4 | | | | https://git.kernel.org/stable/c/5cd99d5aa3d39086bdb53eb5c52df16e98b101a0 | | | | https://linux.oracle.com/cve/CVE-2025-38577.html | | | | https://linux.oracle.com/errata/ELSA-2025-20663.html | | | | https://git.kernel.org/stable/c/42f9ea16aea8b49febaa87950a006a1792209f38 | | | | https://git.kernel.org/stable/c/4732ca17c17f5062426cfa982f43593e6b81963b | | | | https://git.kernel.org/stable/c/880ef748e78a1eb7df2d8e11a9ef21e98bcaabe5 | | | | https://git.kernel.org/stable/c/97df495d754116c8c28ac6a4112f831727bde887 | | | | https://git.kernel.org/stable/c/9bbfe83924946552c4c513099c0e8c83af76311a | | | | https://git.kernel.org/stable/c/a509a55f8eecc8970b3980c6f06886bbff0e2f68 | | | | https://git.kernel.org/stable/c/15df59809c54fbd687cdf27efbd2103a937459be | | | | https://git.kernel.org/stable/c/5cd99d5aa3d39086bdb53eb5c52df16e98b101a0 | | | | https://git.kernel.org/stable/c/9535e440fe5bc6c5ac7cfb407e53bf788b8bf8d4 | | </details> 漏洞分析指导链接: https://gitee.com/openeuler/cve-manager/blob/master/cve-vulner-manager/doc/md/manual.md 漏洞数据来源: 七彩瞬析开源风险感知平台 漏洞补丁信息: <details> <summary>详情(点击展开)</summary> | 影响的包 | 修复版本 | 修复补丁 | 问题引入补丁 | 来源 | | ------- | -------- | ------- | -------- | --------- | | gregkh/linux | | https://git.kernel.org/stable/c/9bbfe83924946552c4c513099c0e8c83af76311a | | ljqc | | | | https://git.kernel.org/stable/c/42f9ea16aea8b49febaa87950a006a1792209f38 | | nvd | | | | https://git.kernel.org/stable/c/4732ca17c17f5062426cfa982f43593e6b81963b | | nvd | | | | https://git.kernel.org/stable/c/880ef748e78a1eb7df2d8e11a9ef21e98bcaabe5 | | nvd | | | | https://git.kernel.org/stable/c/97df495d754116c8c28ac6a4112f831727bde887 | | nvd | | | | https://git.kernel.org/stable/c/9bbfe83924946552c4c513099c0e8c83af76311a | | nvd | | | | https://git.kernel.org/stable/c/a509a55f8eecc8970b3980c6f06886bbff0e2f68 | | nvd | | | | https://git.kernel.org/stable/c/42f9ea16aea8b49febaa87950a006a1792209f38 | | avd | | | | https://git.kernel.org/stable/c/4732ca17c17f5062426cfa982f43593e6b81963b | | avd | | | | https://git.kernel.org/stable/c/880ef748e78a1eb7df2d8e11a9ef21e98bcaabe5 | | avd | | | | https://git.kernel.org/stable/c/97df495d754116c8c28ac6a4112f831727bde887 | | avd | | | | https://git.kernel.org/stable/c/9bbfe83924946552c4c513099c0e8c83af76311a | | avd | | | | https://git.kernel.org/stable/c/a509a55f8eecc8970b3980c6f06886bbff0e2f68 | | avd | | | | https://git.kernel.org/linus/a509a55f8eecc8970b3980c6f06886bbff0e2f68 | | osv | | | | https://git.kernel.org/stable/c/42f9ea16aea8b49febaa87950a006a1792209f38 | | osv | | | | https://git.kernel.org/stable/c/4732ca17c17f5062426cfa982f43593e6b81963b | | osv | | | | https://git.kernel.org/stable/c/880ef748e78a1eb7df2d8e11a9ef21e98bcaabe5 | | osv | | | | https://git.kernel.org/stable/c/97df495d754116c8c28ac6a4112f831727bde887 | | osv | | | | https://git.kernel.org/stable/c/9bbfe83924946552c4c513099c0e8c83af76311a | | osv | | | | https://git.kernel.org/stable/c/a509a55f8eecc8970b3980c6f06886bbff0e2f68 | | osv | | | | https://git.kernel.org/stable/c/15df59809c54fbd687cdf27efbd2103a937459be | | nvd | | | | https://git.kernel.org/stable/c/5cd99d5aa3d39086bdb53eb5c52df16e98b101a0 | | nvd | | | | https://git.kernel.org/stable/c/9535e440fe5bc6c5ac7cfb407e53bf788b8bf8d4 | | nvd | | | | https://git.kernel.org/stable/c/15df59809c54fbd687cdf27efbd2103a937459be | | cvelistv5 | | | | https://git.kernel.org/stable/c/9535e440fe5bc6c5ac7cfb407e53bf788b8bf8d4 | | cvelistv5 | | | | https://git.kernel.org/stable/c/5cd99d5aa3d39086bdb53eb5c52df16e98b101a0 | | cvelistv5 | | | | https://git.kernel.org/stable/c/42f9ea16aea8b49febaa87950a006a1792209f38 | | snyk | | | | https://git.kernel.org/stable/c/4732ca17c17f5062426cfa982f43593e6b81963b | | snyk | | | | https://git.kernel.org/stable/c/880ef748e78a1eb7df2d8e11a9ef21e98bcaabe5 | | snyk | | | | https://git.kernel.org/stable/c/97df495d754116c8c28ac6a4112f831727bde887 | | snyk | | | | https://git.kernel.org/stable/c/9bbfe83924946552c4c513099c0e8c83af76311a | | snyk | | | | https://git.kernel.org/stable/c/a509a55f8eecc8970b3980c6f06886bbff0e2f68 | | snyk | | | | https://git.kernel.org/stable/c/15df59809c54fbd687cdf27efbd2103a937459be | | snyk | | | | https://git.kernel.org/stable/c/5cd99d5aa3d39086bdb53eb5c52df16e98b101a0 | | snyk | | | | https://git.kernel.org/stable/c/9535e440fe5bc6c5ac7cfb407e53bf788b8bf8d4 | | snyk | </details> 二、漏洞分析结构反馈 影响性分析说明: In the Linux kernel, the following vulnerability has been resolved:f2fs: fix to avoid panic in f2fs_evict_inodeAs syzbot [1] reported as below:R10: 0000000000000100 R11: 0000000000000206 R12: 00007ffe17473450R13: 00007f28b1c10854 R14: 000000000000dae5 R15: 00007ffe17474520 </TASK>---[ end trace 0000000000000000 ]---==================================================================BUG: KASAN: use-after-free in __list_del_entry_valid+0xa6/0x130 lib/list_debug.c:62Read of size 8 at addr ffff88812d962278 by task syz-executor/564CPU: 1 PID: 564 Comm: syz-executor Tainted: G W 6.1.129-syzkaller #0Hardware name: Google Google Compute Engine/Google Compute Engine, BIOS Google 02/12/2025Call Trace: <TASK> __dump_stack+0x21/0x24 lib/dump_stack.c:88 dump_stack_lvl+0xee/0x158 lib/dump_stack.c:106 print_address_description+0x71/0x210 mm/kasan/report.c:316 print_report+0x4a/0x60 mm/kasan/report.c:427 kasan_report+0x122/0x150 mm/kasan/report.c:531 __asan_report_load8_noabort+0x14/0x20 mm/kasan/report_generic.c:351 __list_del_entry_valid+0xa6/0x130 lib/list_debug.c:62 __list_del_entry include/linux/list.h:134 [inline] list_del_init include/linux/list.h:206 [inline] f2fs_inode_synced+0xf7/0x2e0 fs/f2fs/super.c:1531 f2fs_update_inode+0x74/0x1c40 fs/f2fs/inode.c:585 f2fs_update_inode_page+0x137/0x170 fs/f2fs/inode.c:703 f2fs_write_inode+0x4ec/0x770 fs/f2fs/inode.c:731 write_inode fs/fs-writeback.c:1460 [inline] __writeback_single_inode+0x4a0/0xab0 fs/fs-writeback.c:1677 writeback_single_inode+0x221/0x8b0 fs/fs-writeback.c:1733 sync_inode_metadata+0xb6/0x110 fs/fs-writeback.c:2789 f2fs_sync_inode_meta+0x16d/0x2a0 fs/f2fs/checkpoint.c:1159 block_operations fs/f2fs/checkpoint.c:1269 [inline] f2fs_write_checkpoint+0xca3/0x2100 fs/f2fs/checkpoint.c:1658 kill_f2fs_super+0x231/0x390 fs/f2fs/super.c:4668 deactivate_locked_super+0x98/0x100 fs/super.c:332 deactivate_super+0xaf/0xe0 fs/super.c:363 cleanup_mnt+0x45f/0x4e0 fs/namespace.c:1186 __cleanup_mnt+0x19/0x20 fs/namespace.c:1193 task_work_run+0x1c6/0x230 kernel/task_work.c:203 exit_task_work include/linux/task_work.h:39 [inline] do_exit+0x9fb/0x2410 kernel/exit.c:871 do_group_exit+0x210/0x2d0 kernel/exit.c:1021 __do_sys_exit_group kernel/exit.c:1032 [inline] __se_sys_exit_group kernel/exit.c:1030 [inline] __x64_sys_exit_group+0x3f/0x40 kernel/exit.c:1030 x64_sys_call+0x7b4/0x9a0 arch/x86/include/generated/asm/syscalls_64.h:232 do_syscall_x64 arch/x86/entry/common.c:51 [inline] do_syscall_64+0x4c/0xa0 arch/x86/entry/common.c:81 entry_SYSCALL_64_after_hwframe+0x68/0xd2RIP: 0033:0x7f28b1b8e169Code: Unable to access opcode bytes at 0x7f28b1b8e13f.RSP: 002b:00007ffe174710a8 EFLAGS: 00000246 ORIG_RAX: 00000000000000e7RAX: ffffffffffffffda RBX: 00007f28b1c10879 RCX: 00007f28b1b8e169RDX: 0000000000000000 RSI: 0000000000000000 RDI: 0000000000000001RBP: 0000000000000002 R08: 00007ffe1746ee47 R09: 00007ffe17472360R10: 0000000000000009 R11: 0000000000000246 R12: 00007ffe17472360R13: 00007f28b1c10854 R14: 000000000000dae5 R15: 00007ffe17474520 </TASK>Allocated by task 569: kasan_save_stack mm/kasan/common.c:45 [inline] kasan_set_track+0x4b/0x70 mm/kasan/common.c:52 kasan_save_alloc_info+0x25/0x30 mm/kasan/generic.c:505 __kasan_slab_alloc+0x72/0x80 mm/kasan/common.c:328 kasan_slab_alloc include/linux/kasan.h:201 [inline] slab_post_alloc_hook+0x4f/0x2c0 mm/slab.h:737 slab_alloc_node mm/slub.c:3398 [inline] slab_alloc mm/slub.c:3406 [inline] __kmem_cache_alloc_lru mm/slub.c:3413 [inline] kmem_cache_alloc_lru+0x104/0x220 mm/slub.c:3429 alloc_inode_sb include/linux/fs.h:3245 [inline] f2fs_alloc_inode+0x2d/0x340 fs/f2fs/super.c:1419 alloc_inode fs/inode.c:261 [inline] iget_locked+0x186/0x880 fs/inode.c:1373 f2fs_iget+0x55/0x4c60 fs/f2fs/inode.c:483 f2fs_lookup+0x366/0xab0 fs/f2fs/namei.c:487 __lookup_slow+0x2a3/0x3d0 fs/namei.c:1690 lookup_slow+0x57/0x70 fs/namei.c:1707 walk_component+0x2e6/0x410 fs/namei---truncated--- openEuler评分: 3.9 Vector:CVSS:3.0/AV:L/AC:H/PR:H/UI:N/S:U/C:L/I:L/A:L 受影响版本排查(受影响/不受影响): 1.master(6.12.33):不受影响 2.openEuler-20.03-LTS-SP4(4.19.90):不受影响 3.openEuler-22.03-LTS-SP3(5.10.0):不受影响 4.openEuler-22.03-LTS-SP4(5.10.0):不受影响 5.openEuler-24.03-LTS:不受影响 6.openEuler-24.03-LTS-Next:不受影响 7.openEuler-24.03-LTS-SP1:不受影响 8.openEuler-24.03-LTS-SP2:不受影响 修复是否涉及abi变化(是/否): 1.master(6.12.33):否 2.openEuler-20.03-LTS-SP4(4.19.90):否 3.openEuler-22.03-LTS-SP3(5.10.0):否 4.openEuler-22.03-LTS-SP4(5.10.0):否 5.openEuler-24.03-LTS:否 6.openEuler-24.03-LTS-Next:否 7.openEuler-24.03-LTS-SP1:否 8.openEuler-24.03-LTS-SP2:否 原因说明: 1.openEuler-20.03-LTS-SP4(4.19.90):不受影响-组件不存在 2.openEuler-22.03-LTS-SP3(5.10.0):不受影响-组件不存在 3.openEuler-22.03-LTS-SP4(5.10.0):不受影响-组件不存在 4.openEuler-24.03-LTS:不受影响-组件不存在 5.openEuler-24.03-LTS-SP1:不受影响-组件不存在 6.openEuler-24.03-LTS-SP2:不受影响-组件不存在 7.master(6.12.33):不受影响-漏洞代码不能被攻击者触发 8.openEuler-24.03-LTS-Next:不受影响-漏洞代码不能被攻击者触发
一、漏洞信息 漏洞编号:[CVE-2025-38577](https://nvd.nist.gov/vuln/detail/CVE-2025-38577) 漏洞归属组件:[kernel](https://gitee.com/src-openeuler/kernel) 漏洞归属的版本:4.19.140,4.19.194,4.19.90,5.10.0,6.1.19,6.4.0,6.6.0 CVSS V3.0分值: BaseScore:N/A None Vector:CVSS:3.0/ 漏洞简述: In the Linux kernel, the following vulnerability has been resolved:f2fs: fix to avoid panic in f2fs_evict_inodeAs syzbot [1] reported as below:R10: 0000000000000100 R11: 0000000000000206 R12: 00007ffe17473450R13: 00007f28b1c10854 R14: 000000000000dae5 R15: 00007ffe17474520 </TASK>---[ end trace 0000000000000000 ]---==================================================================BUG: KASAN: use-after-free in __list_del_entry_valid+0xa6/0x130 lib/list_debug.c:62Read of size 8 at addr ffff88812d962278 by task syz-executor/564CPU: 1 PID: 564 Comm: syz-executor Tainted: G W 6.1.129-syzkaller #0Hardware name: Google Google Compute Engine/Google Compute Engine, BIOS Google 02/12/2025Call Trace: <TASK> __dump_stack+0x21/0x24 lib/dump_stack.c:88 dump_stack_lvl+0xee/0x158 lib/dump_stack.c:106 print_address_description+0x71/0x210 mm/kasan/report.c:316 print_report+0x4a/0x60 mm/kasan/report.c:427 kasan_report+0x122/0x150 mm/kasan/report.c:531 __asan_report_load8_noabort+0x14/0x20 mm/kasan/report_generic.c:351 __list_del_entry_valid+0xa6/0x130 lib/list_debug.c:62 __list_del_entry include/linux/list.h:134 [inline] list_del_init include/linux/list.h:206 [inline] f2fs_inode_synced+0xf7/0x2e0 fs/f2fs/super.c:1531 f2fs_update_inode+0x74/0x1c40 fs/f2fs/inode.c:585 f2fs_update_inode_page+0x137/0x170 fs/f2fs/inode.c:703 f2fs_write_inode+0x4ec/0x770 fs/f2fs/inode.c:731 write_inode fs/fs-writeback.c:1460 [inline] __writeback_single_inode+0x4a0/0xab0 fs/fs-writeback.c:1677 writeback_single_inode+0x221/0x8b0 fs/fs-writeback.c:1733 sync_inode_metadata+0xb6/0x110 fs/fs-writeback.c:2789 f2fs_sync_inode_meta+0x16d/0x2a0 fs/f2fs/checkpoint.c:1159 block_operations fs/f2fs/checkpoint.c:1269 [inline] f2fs_write_checkpoint+0xca3/0x2100 fs/f2fs/checkpoint.c:1658 kill_f2fs_super+0x231/0x390 fs/f2fs/super.c:4668 deactivate_locked_super+0x98/0x100 fs/super.c:332 deactivate_super+0xaf/0xe0 fs/super.c:363 cleanup_mnt+0x45f/0x4e0 fs/namespace.c:1186 __cleanup_mnt+0x19/0x20 fs/namespace.c:1193 task_work_run+0x1c6/0x230 kernel/task_work.c:203 exit_task_work include/linux/task_work.h:39 [inline] do_exit+0x9fb/0x2410 kernel/exit.c:871 do_group_exit+0x210/0x2d0 kernel/exit.c:1021 __do_sys_exit_group kernel/exit.c:1032 [inline] __se_sys_exit_group kernel/exit.c:1030 [inline] __x64_sys_exit_group+0x3f/0x40 kernel/exit.c:1030 x64_sys_call+0x7b4/0x9a0 arch/x86/include/generated/asm/syscalls_64.h:232 do_syscall_x64 arch/x86/entry/common.c:51 [inline] do_syscall_64+0x4c/0xa0 arch/x86/entry/common.c:81 entry_SYSCALL_64_after_hwframe+0x68/0xd2RIP: 0033:0x7f28b1b8e169Code: Unable to access opcode bytes at 0x7f28b1b8e13f.RSP: 002b:00007ffe174710a8 EFLAGS: 00000246 ORIG_RAX: 00000000000000e7RAX: ffffffffffffffda RBX: 00007f28b1c10879 RCX: 00007f28b1b8e169RDX: 0000000000000000 RSI: 0000000000000000 RDI: 0000000000000001RBP: 0000000000000002 R08: 00007ffe1746ee47 R09: 00007ffe17472360R10: 0000000000000009 R11: 0000000000000246 R12: 00007ffe17472360R13: 00007f28b1c10854 R14: 000000000000dae5 R15: 00007ffe17474520 </TASK>Allocated by task 569: kasan_save_stack mm/kasan/common.c:45 [inline] kasan_set_track+0x4b/0x70 mm/kasan/common.c:52 kasan_save_alloc_info+0x25/0x30 mm/kasan/generic.c:505 __kasan_slab_alloc+0x72/0x80 mm/kasan/common.c:328 kasan_slab_alloc include/linux/kasan.h:201 [inline] slab_post_alloc_hook+0x4f/0x2c0 mm/slab.h:737 slab_alloc_node mm/slub.c:3398 [inline] slab_alloc mm/slub.c:3406 [inline] __kmem_cache_alloc_lru mm/slub.c:3413 [inline] kmem_cache_alloc_lru+0x104/0x220 mm/slub.c:3429 alloc_inode_sb include/linux/fs.h:3245 [inline] f2fs_alloc_inode+0x2d/0x340 fs/f2fs/super.c:1419 alloc_inode fs/inode.c:261 [inline] iget_locked+0x186/0x880 fs/inode.c:1373 f2fs_iget+0x55/0x4c60 fs/f2fs/inode.c:483 f2fs_lookup+0x366/0xab0 fs/f2fs/namei.c:487 __lookup_slow+0x2a3/0x3d0 fs/namei.c:1690 lookup_slow+0x57/0x70 fs/namei.c:1707 walk_component+0x2e6/0x410 fs/namei---truncated--- 漏洞公开时间:2025-08-20 01:15:34 漏洞创建时间:2025-08-22 10:36:15 漏洞详情参考链接: https://nvd.nist.gov/vuln/detail/CVE-2025-38577 <details> <summary>更多参考(点击展开)</summary> | 参考来源 | 参考链接 | 来源链接 | | ------- | -------- | -------- | | | https://git.kernel.org/stable/c/42f9ea16aea8b49febaa87950a006a1792209f38 | | | | https://git.kernel.org/stable/c/4732ca17c17f5062426cfa982f43593e6b81963b | | | | https://git.kernel.org/stable/c/880ef748e78a1eb7df2d8e11a9ef21e98bcaabe5 | | | | https://git.kernel.org/stable/c/97df495d754116c8c28ac6a4112f831727bde887 | | | | https://git.kernel.org/stable/c/9bbfe83924946552c4c513099c0e8c83af76311a | | | | https://git.kernel.org/stable/c/a509a55f8eecc8970b3980c6f06886bbff0e2f68 | | | | https://security-tracker.debian.org/tracker/CVE-2025-38577 | | | | https://lore.kernel.org/linux-cve-announce/2025081912-CVE-2025-38577-f225@gregkh/T/#u | | | | https://git.kernel.org/stable/c/42f9ea16aea8b49febaa87950a006a1792209f38 | | | | https://git.kernel.org/stable/c/4732ca17c17f5062426cfa982f43593e6b81963b | | | | https://git.kernel.org/stable/c/880ef748e78a1eb7df2d8e11a9ef21e98bcaabe5 | | | | https://git.kernel.org/stable/c/97df495d754116c8c28ac6a4112f831727bde887 | | | | https://git.kernel.org/stable/c/9bbfe83924946552c4c513099c0e8c83af76311a | | | | https://git.kernel.org/stable/c/a509a55f8eecc8970b3980c6f06886bbff0e2f68 | | | | https://www.cve.org/CVERecord?id=CVE-2025-38577 | | | | https://lore.kernel.org/linux-cve-announce/2025081912-CVE-2025-38577-f225@gregkh/T | | | | https://bugzilla.redhat.com/show_bug.cgi?id=2389500 | | | | https://ubuntu.com/security/CVE-2025-38577 | | | | https://www.cve.org/CVERecord?id=CVE-2025-38577 | | | | https://git.kernel.org/linus/a509a55f8eecc8970b3980c6f06886bbff0e2f68 | | | | https://git.kernel.org/stable/c/42f9ea16aea8b49febaa87950a006a1792209f38 | | | | https://git.kernel.org/stable/c/4732ca17c17f5062426cfa982f43593e6b81963b | | | | https://git.kernel.org/stable/c/880ef748e78a1eb7df2d8e11a9ef21e98bcaabe5 | | | | https://git.kernel.org/stable/c/97df495d754116c8c28ac6a4112f831727bde887 | | | | https://git.kernel.org/stable/c/9bbfe83924946552c4c513099c0e8c83af76311a | | | | https://git.kernel.org/stable/c/a509a55f8eecc8970b3980c6f06886bbff0e2f68 | | | | https://docs.bell-sw.com/security/cves/CVE-2025-38577 | | | | https://nvd.nist.gov/vuln/detail/CVE-2025-38577 | | | | https://git.kernel.org/stable/c/15df59809c54fbd687cdf27efbd2103a937459be | | | | https://git.kernel.org/stable/c/5cd99d5aa3d39086bdb53eb5c52df16e98b101a0 | | | | https://git.kernel.org/stable/c/9535e440fe5bc6c5ac7cfb407e53bf788b8bf8d4 | | | | https://git.kernel.org/stable/c/15df59809c54fbd687cdf27efbd2103a937459be | | | | https://git.kernel.org/stable/c/9535e440fe5bc6c5ac7cfb407e53bf788b8bf8d4 | | | | https://git.kernel.org/stable/c/5cd99d5aa3d39086bdb53eb5c52df16e98b101a0 | | | | https://linux.oracle.com/cve/CVE-2025-38577.html | | | | https://linux.oracle.com/errata/ELSA-2025-20663.html | | | | https://git.kernel.org/stable/c/42f9ea16aea8b49febaa87950a006a1792209f38 | | | | https://git.kernel.org/stable/c/4732ca17c17f5062426cfa982f43593e6b81963b | | | | https://git.kernel.org/stable/c/880ef748e78a1eb7df2d8e11a9ef21e98bcaabe5 | | | | https://git.kernel.org/stable/c/97df495d754116c8c28ac6a4112f831727bde887 | | | | https://git.kernel.org/stable/c/9bbfe83924946552c4c513099c0e8c83af76311a | | | | https://git.kernel.org/stable/c/a509a55f8eecc8970b3980c6f06886bbff0e2f68 | | | | https://git.kernel.org/stable/c/15df59809c54fbd687cdf27efbd2103a937459be | | | | https://git.kernel.org/stable/c/5cd99d5aa3d39086bdb53eb5c52df16e98b101a0 | | | | https://git.kernel.org/stable/c/9535e440fe5bc6c5ac7cfb407e53bf788b8bf8d4 | | </details> 漏洞分析指导链接: https://gitee.com/openeuler/cve-manager/blob/master/cve-vulner-manager/doc/md/manual.md 漏洞数据来源: 七彩瞬析开源风险感知平台 漏洞补丁信息: <details> <summary>详情(点击展开)</summary> | 影响的包 | 修复版本 | 修复补丁 | 问题引入补丁 | 来源 | | ------- | -------- | ------- | -------- | --------- | | gregkh/linux | | https://git.kernel.org/stable/c/9bbfe83924946552c4c513099c0e8c83af76311a | | ljqc | | | | https://git.kernel.org/stable/c/42f9ea16aea8b49febaa87950a006a1792209f38 | | nvd | | | | https://git.kernel.org/stable/c/4732ca17c17f5062426cfa982f43593e6b81963b | | nvd | | | | https://git.kernel.org/stable/c/880ef748e78a1eb7df2d8e11a9ef21e98bcaabe5 | | nvd | | | | https://git.kernel.org/stable/c/97df495d754116c8c28ac6a4112f831727bde887 | | nvd | | | | https://git.kernel.org/stable/c/9bbfe83924946552c4c513099c0e8c83af76311a | | nvd | | | | https://git.kernel.org/stable/c/a509a55f8eecc8970b3980c6f06886bbff0e2f68 | | nvd | | | | https://git.kernel.org/stable/c/42f9ea16aea8b49febaa87950a006a1792209f38 | | avd | | | | https://git.kernel.org/stable/c/4732ca17c17f5062426cfa982f43593e6b81963b | | avd | | | | https://git.kernel.org/stable/c/880ef748e78a1eb7df2d8e11a9ef21e98bcaabe5 | | avd | | | | https://git.kernel.org/stable/c/97df495d754116c8c28ac6a4112f831727bde887 | | avd | | | | https://git.kernel.org/stable/c/9bbfe83924946552c4c513099c0e8c83af76311a | | avd | | | | https://git.kernel.org/stable/c/a509a55f8eecc8970b3980c6f06886bbff0e2f68 | | avd | | | | https://git.kernel.org/linus/a509a55f8eecc8970b3980c6f06886bbff0e2f68 | | osv | | | | https://git.kernel.org/stable/c/42f9ea16aea8b49febaa87950a006a1792209f38 | | osv | | | | https://git.kernel.org/stable/c/4732ca17c17f5062426cfa982f43593e6b81963b | | osv | | | | https://git.kernel.org/stable/c/880ef748e78a1eb7df2d8e11a9ef21e98bcaabe5 | | osv | | | | https://git.kernel.org/stable/c/97df495d754116c8c28ac6a4112f831727bde887 | | osv | | | | https://git.kernel.org/stable/c/9bbfe83924946552c4c513099c0e8c83af76311a | | osv | | | | https://git.kernel.org/stable/c/a509a55f8eecc8970b3980c6f06886bbff0e2f68 | | osv | | | | https://git.kernel.org/stable/c/15df59809c54fbd687cdf27efbd2103a937459be | | nvd | | | | https://git.kernel.org/stable/c/5cd99d5aa3d39086bdb53eb5c52df16e98b101a0 | | nvd | | | | https://git.kernel.org/stable/c/9535e440fe5bc6c5ac7cfb407e53bf788b8bf8d4 | | nvd | | | | https://git.kernel.org/stable/c/15df59809c54fbd687cdf27efbd2103a937459be | | cvelistv5 | | | | https://git.kernel.org/stable/c/9535e440fe5bc6c5ac7cfb407e53bf788b8bf8d4 | | cvelistv5 | | | | https://git.kernel.org/stable/c/5cd99d5aa3d39086bdb53eb5c52df16e98b101a0 | | cvelistv5 | | | | https://git.kernel.org/stable/c/42f9ea16aea8b49febaa87950a006a1792209f38 | | snyk | | | | https://git.kernel.org/stable/c/4732ca17c17f5062426cfa982f43593e6b81963b | | snyk | | | | https://git.kernel.org/stable/c/880ef748e78a1eb7df2d8e11a9ef21e98bcaabe5 | | snyk | | | | https://git.kernel.org/stable/c/97df495d754116c8c28ac6a4112f831727bde887 | | snyk | | | | https://git.kernel.org/stable/c/9bbfe83924946552c4c513099c0e8c83af76311a | | snyk | | | | https://git.kernel.org/stable/c/a509a55f8eecc8970b3980c6f06886bbff0e2f68 | | snyk | | | | https://git.kernel.org/stable/c/15df59809c54fbd687cdf27efbd2103a937459be | | snyk | | | | https://git.kernel.org/stable/c/5cd99d5aa3d39086bdb53eb5c52df16e98b101a0 | | snyk | | | | https://git.kernel.org/stable/c/9535e440fe5bc6c5ac7cfb407e53bf788b8bf8d4 | | snyk | </details> 二、漏洞分析结构反馈 影响性分析说明: In the Linux kernel, the following vulnerability has been resolved:f2fs: fix to avoid panic in f2fs_evict_inodeAs syzbot [1] reported as below:R10: 0000000000000100 R11: 0000000000000206 R12: 00007ffe17473450R13: 00007f28b1c10854 R14: 000000000000dae5 R15: 00007ffe17474520 </TASK>---[ end trace 0000000000000000 ]---==================================================================BUG: KASAN: use-after-free in __list_del_entry_valid+0xa6/0x130 lib/list_debug.c:62Read of size 8 at addr ffff88812d962278 by task syz-executor/564CPU: 1 PID: 564 Comm: syz-executor Tainted: G W 6.1.129-syzkaller #0Hardware name: Google Google Compute Engine/Google Compute Engine, BIOS Google 02/12/2025Call Trace: <TASK> __dump_stack+0x21/0x24 lib/dump_stack.c:88 dump_stack_lvl+0xee/0x158 lib/dump_stack.c:106 print_address_description+0x71/0x210 mm/kasan/report.c:316 print_report+0x4a/0x60 mm/kasan/report.c:427 kasan_report+0x122/0x150 mm/kasan/report.c:531 __asan_report_load8_noabort+0x14/0x20 mm/kasan/report_generic.c:351 __list_del_entry_valid+0xa6/0x130 lib/list_debug.c:62 __list_del_entry include/linux/list.h:134 [inline] list_del_init include/linux/list.h:206 [inline] f2fs_inode_synced+0xf7/0x2e0 fs/f2fs/super.c:1531 f2fs_update_inode+0x74/0x1c40 fs/f2fs/inode.c:585 f2fs_update_inode_page+0x137/0x170 fs/f2fs/inode.c:703 f2fs_write_inode+0x4ec/0x770 fs/f2fs/inode.c:731 write_inode fs/fs-writeback.c:1460 [inline] __writeback_single_inode+0x4a0/0xab0 fs/fs-writeback.c:1677 writeback_single_inode+0x221/0x8b0 fs/fs-writeback.c:1733 sync_inode_metadata+0xb6/0x110 fs/fs-writeback.c:2789 f2fs_sync_inode_meta+0x16d/0x2a0 fs/f2fs/checkpoint.c:1159 block_operations fs/f2fs/checkpoint.c:1269 [inline] f2fs_write_checkpoint+0xca3/0x2100 fs/f2fs/checkpoint.c:1658 kill_f2fs_super+0x231/0x390 fs/f2fs/super.c:4668 deactivate_locked_super+0x98/0x100 fs/super.c:332 deactivate_super+0xaf/0xe0 fs/super.c:363 cleanup_mnt+0x45f/0x4e0 fs/namespace.c:1186 __cleanup_mnt+0x19/0x20 fs/namespace.c:1193 task_work_run+0x1c6/0x230 kernel/task_work.c:203 exit_task_work include/linux/task_work.h:39 [inline] do_exit+0x9fb/0x2410 kernel/exit.c:871 do_group_exit+0x210/0x2d0 kernel/exit.c:1021 __do_sys_exit_group kernel/exit.c:1032 [inline] __se_sys_exit_group kernel/exit.c:1030 [inline] __x64_sys_exit_group+0x3f/0x40 kernel/exit.c:1030 x64_sys_call+0x7b4/0x9a0 arch/x86/include/generated/asm/syscalls_64.h:232 do_syscall_x64 arch/x86/entry/common.c:51 [inline] do_syscall_64+0x4c/0xa0 arch/x86/entry/common.c:81 entry_SYSCALL_64_after_hwframe+0x68/0xd2RIP: 0033:0x7f28b1b8e169Code: Unable to access opcode bytes at 0x7f28b1b8e13f.RSP: 002b:00007ffe174710a8 EFLAGS: 00000246 ORIG_RAX: 00000000000000e7RAX: ffffffffffffffda RBX: 00007f28b1c10879 RCX: 00007f28b1b8e169RDX: 0000000000000000 RSI: 0000000000000000 RDI: 0000000000000001RBP: 0000000000000002 R08: 00007ffe1746ee47 R09: 00007ffe17472360R10: 0000000000000009 R11: 0000000000000246 R12: 00007ffe17472360R13: 00007f28b1c10854 R14: 000000000000dae5 R15: 00007ffe17474520 </TASK>Allocated by task 569: kasan_save_stack mm/kasan/common.c:45 [inline] kasan_set_track+0x4b/0x70 mm/kasan/common.c:52 kasan_save_alloc_info+0x25/0x30 mm/kasan/generic.c:505 __kasan_slab_alloc+0x72/0x80 mm/kasan/common.c:328 kasan_slab_alloc include/linux/kasan.h:201 [inline] slab_post_alloc_hook+0x4f/0x2c0 mm/slab.h:737 slab_alloc_node mm/slub.c:3398 [inline] slab_alloc mm/slub.c:3406 [inline] __kmem_cache_alloc_lru mm/slub.c:3413 [inline] kmem_cache_alloc_lru+0x104/0x220 mm/slub.c:3429 alloc_inode_sb include/linux/fs.h:3245 [inline] f2fs_alloc_inode+0x2d/0x340 fs/f2fs/super.c:1419 alloc_inode fs/inode.c:261 [inline] iget_locked+0x186/0x880 fs/inode.c:1373 f2fs_iget+0x55/0x4c60 fs/f2fs/inode.c:483 f2fs_lookup+0x366/0xab0 fs/f2fs/namei.c:487 __lookup_slow+0x2a3/0x3d0 fs/namei.c:1690 lookup_slow+0x57/0x70 fs/namei.c:1707 walk_component+0x2e6/0x410 fs/namei---truncated--- openEuler评分: 3.9 Vector:CVSS:3.0/AV:L/AC:H/PR:H/UI:N/S:U/C:L/I:L/A:L 受影响版本排查(受影响/不受影响): 1.master(6.12.33):不受影响 2.openEuler-20.03-LTS-SP4(4.19.90):不受影响 3.openEuler-22.03-LTS-SP3(5.10.0):不受影响 4.openEuler-22.03-LTS-SP4(5.10.0):不受影响 5.openEuler-24.03-LTS:不受影响 6.openEuler-24.03-LTS-Next:不受影响 7.openEuler-24.03-LTS-SP1:不受影响 8.openEuler-24.03-LTS-SP2:不受影响 修复是否涉及abi变化(是/否): 1.master(6.12.33):否 2.openEuler-20.03-LTS-SP4(4.19.90):否 3.openEuler-22.03-LTS-SP3(5.10.0):否 4.openEuler-22.03-LTS-SP4(5.10.0):否 5.openEuler-24.03-LTS:否 6.openEuler-24.03-LTS-Next:否 7.openEuler-24.03-LTS-SP1:否 8.openEuler-24.03-LTS-SP2:否 原因说明: 1.openEuler-20.03-LTS-SP4(4.19.90):不受影响-组件不存在 2.openEuler-22.03-LTS-SP3(5.10.0):不受影响-组件不存在 3.openEuler-22.03-LTS-SP4(5.10.0):不受影响-组件不存在 4.openEuler-24.03-LTS:不受影响-组件不存在 5.openEuler-24.03-LTS-SP1:不受影响-组件不存在 6.openEuler-24.03-LTS-SP2:不受影响-组件不存在 7.master(6.12.33):不受影响-漏洞代码不能被攻击者触发 8.openEuler-24.03-LTS-Next:不受影响-漏洞代码不能被攻击者触发
Comments (
5
)
Sign in
to comment
Status
Done
Backlog
已挂起
Doing
Done
Declined
Assignees
Not set
CTC-Xibo.Wang
CTC-XiboWang
Assignee
Collaborator
+Assign
+Mention
Labels
CVE/UNAFFECTED
sig/Kernel
Not set
Projects
Unprojected
Unprojected
Milestones
No related milestones
No related milestones
Pull Requests
None yet
None yet
Successfully merging a pull request will close this issue.
Branches
No related branch
Branches (
-
)
Tags (
-
)
Planed to start   -   Planed to end
-
Top level
Not Top
Top Level: High
Top Level: Medium
Top Level: Low
Priority
Not specified
Serious
Main
Secondary
Unimportant
Duration
(hours)
参与者(2)
1
https://gitee.com/src-openeuler/kernel.git
git@gitee.com:src-openeuler/kernel.git
src-openeuler
kernel
kernel
Going to Help Center
Search
Git 命令在线学习
如何在 Gitee 导入 GitHub 仓库
Git 仓库基础操作
企业版和社区版功能对比
SSH 公钥设置
如何处理代码冲突
仓库体积过大,如何减小?
如何找回被删除的仓库数据
Gitee 产品配额说明
GitHub仓库快速导入Gitee及同步更新
什么是 Release(发行版)
将 PHP 项目自动发布到 packagist.org
Repository Report
Back to the top
Login prompt
This operation requires login to the code cloud account. Please log in before operating.
Go to login
No account. Register