CVE-2025-38167: fs/ntfs3: handle hdr_first_de() return value
Published Jul 3, 2025
·Updated
fs/ntfs3: handle hdrfirstde() return value
Affected Software
8 affected componentsFixes available
Linux Kernel
Linux Linux kernel>=5.15<5.15.186
Linux Linux kernel>=5.16<6.1.142
Linux Linux kernel>=6.2<6.6.94
Linux Linux kernel>=6.7<6.12.34
Linux Linux kernel>=6.13<6.15.3
Debian Debian Linux=11.0
Microsoft azl3 kernel 6.6.92.2-2
Event History
Jul 3, 2025
CVE Published
via MITRE·08:36 AM
Data Sourced
via MITRE·08:36 AM
Description
Data Sourced
via NVD·09:15 AM
RemedyDescriptionSeverityWeaknessAffected Software
Aug 7, 2025
Data Sourced
via Microsoft·07:00 AM
DescriptionSeverityWeakness
Data Sourced
via Microsoft·07:00 AM
Affected Software
Updated
via Microsoft·07:00 AM
DescriptionSeverity
Frequently Asked Questions
1
What is the severity of CVE-2025-38167?
CVE-2025-38167 is classified as a medium severity vulnerability in the Linux kernel.
2
How do I fix CVE-2025-38167?
To fix CVE-2025-38167, update your Linux kernel to the latest version where the vulnerability has been addressed.
3
What systems are affected by CVE-2025-38167?
CVE-2025-38167 affects various versions of the Linux kernel that utilize the ntfs3 file system.
4
What type of issue is CVE-2025-38167?
CVE-2025-38167 is a null pointer dereference issue in the Linux kernel's handling of NTFS file systems.
5
Are there any known exploits for CVE-2025-38167?
As of now, there are no publicly available exploits reported for CVE-2025-38167.