Memory Corruption Vulnerability in Linux Kernel Affects exFAT Filesystem
CVE-2025-40307
What is CVE-2025-40307?
A memory corruption vulnerability exists in the exFAT implementation of the Linux kernel. When creating an exFAT image with improperly set cluster bits in the allocation bitmap, it allows potential exploitation where existing entries may be deleted and reclaimed incorrectly. The vulnerabilities stem from the lack of validation for the cluster allocation bitmap when directories are created, which can lead to inconsistencies within the filesystem. The recent patch introduces validation checks to ensure that the clusters designated for allocation are indeed marked as in-use, thereby mitigating these risks.
Affected Version(s)
Linux 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 < 6bc58b4c53795ab5fe00648344aa7d9d61175f90
Linux 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 < 13c1d24803d5b0446b3f6f0fdd67e07ac1fdc7bf
Linux 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 < 79c1587b6cda74deb0c86fc7ba194b92958c793c