Memory Corruption Vulnerability in Linux Kernel Affects exFAT Filesystem
CVE-2025-40307

Currently unrated

Key Information:

Vendor

Linux

Status
Vendor
CVE Published:
8 December 2025

What is CVE-2025-40307?

A memory corruption vulnerability exists in the exFAT implementation of the Linux kernel. When creating an exFAT image with improperly set cluster bits in the allocation bitmap, it allows potential exploitation where existing entries may be deleted and reclaimed incorrectly. The vulnerabilities stem from the lack of validation for the cluster allocation bitmap when directories are created, which can lead to inconsistencies within the filesystem. The recent patch introduces validation checks to ensure that the clusters designated for allocation are indeed marked as in-use, thereby mitigating these risks.

Affected Version(s)

Linux 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 < 6bc58b4c53795ab5fe00648344aa7d9d61175f90

Linux 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 < 13c1d24803d5b0446b3f6f0fdd67e07ac1fdc7bf

Linux 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 < 79c1587b6cda74deb0c86fc7ba194b92958c793c

References

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.