CVE-2025-38660: [ceph] parse_longname(): strrchr() expects NUL-terminated string
Published Aug 22, 2025
·Updated
[ceph] parselongname(): strrchr() expects NUL-terminated string
Affected Software
9 affected components
Linux Kernel
Linux Linux kernel>=6.6<6.12.42
Linux Linux kernel>=6.13<6.15.10
Linux Linux kernel>=6.16<6.16.1
Microsoft azl3 kernel 6.6.117.1-1
Microsoft azl3 kernel 6.6.112.1-2
Microsoft azl3 kernel 6.6.104.2-4
Microsoft azl3 kernel 6.6.96.2-2
Microsoft azl3 kernel 6.6.96.2-1
Event History
Aug 22, 2025
CVE Published
via MITRE·04:01 PM
Data Sourced
via MITRE·04:01 PM
DescriptionSeverity
Data Sourced
via NVD·04:15 PM
RemedyDescriptionSeverityAffected Software
Sep 3, 2025
Data Sourced
via Microsoft·10:14 PM
DescriptionSeverityWeakness
Data Sourced
via Microsoft·10:14 PM
Affected Software
Updated
via Microsoft·10:14 PM
Affected Software
Updated
via Microsoft·10:14 PM
SeverityAffected Software
Updated
via Microsoft·10:14 PM
DescriptionSeverity
Frequently Asked Questions
1
What is the severity of CVE-2025-38660?
CVE-2025-38660 has been classified with a severity rating that indicates a potential impact on the stability and security of the Linux kernel.
2
How do I fix CVE-2025-38660?
To resolve CVE-2025-38660, you should update to the latest patched version of the Linux kernel provided by your distribution.
3
What systems are affected by CVE-2025-38660?
CVE-2025-38660 affects all versions of the Linux kernel that utilize the parse_longname() function without proper string termination.
4
Can CVE-2025-38660 be exploited remotely?
Exploitation of CVE-2025-38660 may depend on the specific configuration and use cases of the affected systems.
5
Is there a workaround for CVE-2025-38660?
Temporarily, users may restrict access to vulnerable features of the Linux kernel until an update can be applied.