In the Linux kernel, the following vulnerability has been resolved:
orangefs: Do not truncate file size
'len' is used to store the result of isizeread(), so making 'len' a size_t results in truncation to 4GiB on 32-bit systems.
[
{
"deprecated": false,
"id": "CVE-2025-38065-257f3e80",
"source": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git@15602508ad2f923e228b9521960b4addcd27d9c4",
"digest": {
"function_hash": "179907887444090268398888862584779469456",
"length": 989.0
},
"target": {
"function": "orangefs_writepage_locked",
"file": "fs/orangefs/inode.c"
},
"signature_type": "Function",
"signature_version": "v1"
},
{
"deprecated": false,
"id": "CVE-2025-38065-2d7b212a",
"source": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git@cd918ec24168fe08c6aafc077dd3b6d88364c5cf",
"digest": {
"function_hash": "8943783642608071860222449366263598823",
"length": 940.0
},
"target": {
"function": "orangefs_writepage_locked",
"file": "fs/orangefs/inode.c"
},
"signature_type": "Function",
"signature_version": "v1"
},
{
"deprecated": false,
"id": "CVE-2025-38065-4ade71d1",
"source": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git@2323b806221e6268a4e17711bc72e2fc87c191a3",
"digest": {
"function_hash": "93457142168128365720274424154951013476",
"length": 1731.0
},
"target": {
"function": "orangefs_writepages_work",
"file": "fs/orangefs/inode.c"
},
"signature_type": "Function",
"signature_version": "v1"
},
{
"deprecated": false,
"id": "CVE-2025-38065-54dfe515",
"source": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git@cd918ec24168fe08c6aafc077dd3b6d88364c5cf",
"digest": {
"threshold": 0.9,
"line_hashes": [
"96291426596754478325794783607542021184",
"3497567731467343092909511658642032220",
"296164022432198132428543177833892821320",
"46290865229141348779021999581575501039",
"135755798929987517000172588943072503372",
"42285795258742251712282980198314400212",
"244118039401601424580595232116452288581",
"132173485697864348889629954949700634439",
"262510480745153792711664193298161820740",
"329192949560662370176998519192720124696",
"45048932251690172327457946554769174634"
]
},
"target": {
"file": "fs/orangefs/inode.c"
},
"signature_type": "Line",
"signature_version": "v1"
},
{
"deprecated": false,
"id": "CVE-2025-38065-5665f2b5",
"source": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git@15602508ad2f923e228b9521960b4addcd27d9c4",
"digest": {
"function_hash": "162914382621849339213350339185310413063",
"length": 1873.0
},
"target": {
"function": "orangefs_writepages_work",
"file": "fs/orangefs/inode.c"
},
"signature_type": "Function",
"signature_version": "v1"
},
{
"deprecated": false,
"id": "CVE-2025-38065-5e62b449",
"source": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git@2323b806221e6268a4e17711bc72e2fc87c191a3",
"digest": {
"threshold": 0.9,
"line_hashes": [
"96291426596754478325794783607542021184",
"3497567731467343092909511658642032220",
"296164022432198132428543177833892821320",
"46290865229141348779021999581575501039",
"135755798929987517000172588943072503372",
"42285795258742251712282980198314400212",
"244118039401601424580595232116452288581",
"132173485697864348889629954949700634439",
"262510480745153792711664193298161820740",
"329192949560662370176998519192720124696",
"45048932251690172327457946554769174634"
]
},
"target": {
"file": "fs/orangefs/inode.c"
},
"signature_type": "Line",
"signature_version": "v1"
},
{
"deprecated": false,
"id": "CVE-2025-38065-61717015",
"source": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git@ceaf195ed285b77791e29016ee6344b3ded609b3",
"digest": {
"threshold": 0.9,
"line_hashes": [
"96291426596754478325794783607542021184",
"3497567731467343092909511658642032220",
"296164022432198132428543177833892821320",
"46290865229141348779021999581575501039",
"135755798929987517000172588943072503372",
"42285795258742251712282980198314400212",
"244118039401601424580595232116452288581",
"132173485697864348889629954949700634439",
"262510480745153792711664193298161820740",
"329192949560662370176998519192720124696",
"45048932251690172327457946554769174634"
]
},
"target": {
"file": "fs/orangefs/inode.c"
},
"signature_type": "Line",
"signature_version": "v1"
},
{
"deprecated": false,
"id": "CVE-2025-38065-64536c76",
"source": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git@062e8093592fb866b8e016641a8b27feb6ac509d",
"digest": {
"threshold": 0.9,
"line_hashes": [
"96291426596754478325794783607542021184",
"3497567731467343092909511658642032220",
"296164022432198132428543177833892821320",
"46290865229141348779021999581575501039",
"135755798929987517000172588943072503372",
"42285795258742251712282980198314400212",
"244118039401601424580595232116452288581",
"132173485697864348889629954949700634439",
"262510480745153792711664193298161820740",
"329192949560662370176998519192720124696",
"45048932251690172327457946554769174634"
]
},
"target": {
"file": "fs/orangefs/inode.c"
},
"signature_type": "Line",
"signature_version": "v1"
},
{
"deprecated": false,
"id": "CVE-2025-38065-6adba9aa",
"source": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git@ceaf195ed285b77791e29016ee6344b3ded609b3",
"digest": {
"function_hash": "34414552939536577611136624247421276469",
"length": 1043.0
},
"target": {
"function": "orangefs_writepage_locked",
"file": "fs/orangefs/inode.c"
},
"signature_type": "Function",
"signature_version": "v1"
},
{
"deprecated": false,
"id": "CVE-2025-38065-822c6a16",
"source": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git@2323b806221e6268a4e17711bc72e2fc87c191a3",
"digest": {
"function_hash": "8943783642608071860222449366263598823",
"length": 940.0
},
"target": {
"function": "orangefs_writepage_locked",
"file": "fs/orangefs/inode.c"
},
"signature_type": "Function",
"signature_version": "v1"
},
{
"deprecated": false,
"id": "CVE-2025-38065-8ac3d7fe",
"source": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git@15602508ad2f923e228b9521960b4addcd27d9c4",
"digest": {
"threshold": 0.9,
"line_hashes": [
"96291426596754478325794783607542021184",
"3497567731467343092909511658642032220",
"296164022432198132428543177833892821320",
"46290865229141348779021999581575501039",
"135755798929987517000172588943072503372",
"42285795258742251712282980198314400212",
"244118039401601424580595232116452288581",
"132173485697864348889629954949700634439",
"262510480745153792711664193298161820740",
"329192949560662370176998519192720124696",
"45048932251690172327457946554769174634"
]
},
"target": {
"file": "fs/orangefs/inode.c"
},
"signature_type": "Line",
"signature_version": "v1"
},
{
"deprecated": false,
"id": "CVE-2025-38065-8bbd56e8",
"source": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git@5111227d7f1f57f6804666b3abf780a23f44fc1d",
"digest": {
"function_hash": "232953796463222698622357676140313497140",
"length": 983.0
},
"target": {
"function": "orangefs_writepage_locked",
"file": "fs/orangefs/inode.c"
},
"signature_type": "Function",
"signature_version": "v1"
},
{
"deprecated": false,
"id": "CVE-2025-38065-ab63929c",
"source": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git@5111227d7f1f57f6804666b3abf780a23f44fc1d",
"digest": {
"function_hash": "153664591785292964843786665027834368118",
"length": 1867.0
},
"target": {
"function": "orangefs_writepages_work",
"file": "fs/orangefs/inode.c"
},
"signature_type": "Function",
"signature_version": "v1"
},
{
"deprecated": false,
"id": "CVE-2025-38065-b147fdda",
"source": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git@062e8093592fb866b8e016641a8b27feb6ac509d",
"digest": {
"function_hash": "8943783642608071860222449366263598823",
"length": 940.0
},
"target": {
"function": "orangefs_writepage_locked",
"file": "fs/orangefs/inode.c"
},
"signature_type": "Function",
"signature_version": "v1"
},
{
"deprecated": false,
"id": "CVE-2025-38065-bcb44b12",
"source": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git@cd918ec24168fe08c6aafc077dd3b6d88364c5cf",
"digest": {
"function_hash": "93457142168128365720274424154951013476",
"length": 1731.0
},
"target": {
"function": "orangefs_writepages_work",
"file": "fs/orangefs/inode.c"
},
"signature_type": "Function",
"signature_version": "v1"
},
{
"deprecated": false,
"id": "CVE-2025-38065-bd86dfee",
"source": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git@ceaf195ed285b77791e29016ee6344b3ded609b3",
"digest": {
"function_hash": "151508500949992445675291274209549057699",
"length": 1860.0
},
"target": {
"function": "orangefs_writepages_work",
"file": "fs/orangefs/inode.c"
},
"signature_type": "Function",
"signature_version": "v1"
},
{
"deprecated": false,
"id": "CVE-2025-38065-e9869cc7",
"source": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git@062e8093592fb866b8e016641a8b27feb6ac509d",
"digest": {
"function_hash": "93457142168128365720274424154951013476",
"length": 1731.0
},
"target": {
"function": "orangefs_writepages_work",
"file": "fs/orangefs/inode.c"
},
"signature_type": "Function",
"signature_version": "v1"
},
{
"deprecated": false,
"id": "CVE-2025-38065-f925164c",
"source": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git@5111227d7f1f57f6804666b3abf780a23f44fc1d",
"digest": {
"threshold": 0.9,
"line_hashes": [
"96291426596754478325794783607542021184",
"3497567731467343092909511658642032220",
"296164022432198132428543177833892821320",
"46290865229141348779021999581575501039",
"135755798929987517000172588943072503372",
"42285795258742251712282980198314400212",
"244118039401601424580595232116452288581",
"132173485697864348889629954949700634439",
"262510480745153792711664193298161820740",
"329192949560662370176998519192720124696",
"45048932251690172327457946554769174634"
]
},
"target": {
"file": "fs/orangefs/inode.c"
},
"signature_type": "Line",
"signature_version": "v1"
}
]