In the Linux kernel, the following vulnerability has been resolved:
exfat: fix double free in delayed_free
The double free could happen in the following path.
exfatcreateupcasetable() exfatcreateupcasetable() : return error exfatfreeupcasetable() : free ->volutbl exfatloaddefaultupcasetable : return error exfatkillsb() delayedfree() exfatfreeupcasetable() <--------- double free This patch set ->vol_util as NULL after freeing it.
[
{
"source": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git@66e84439ec2af776ce749e8540f8fdd257774152",
"deprecated": false,
"digest": {
"function_hash": "226160876767190123673767391459705220353",
"length": 69.0
},
"target": {
"function": "exfat_free_upcase_table",
"file": "fs/exfat/nls.c"
},
"id": "CVE-2025-38206-0bc03feb",
"signature_version": "v1",
"signature_type": "Function"
},
{
"source": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git@66e84439ec2af776ce749e8540f8fdd257774152",
"deprecated": false,
"digest": {
"line_hashes": [
"335577595976639138245316047796532771587",
"55537835885452332754232002452218092124"
],
"threshold": 0.9
},
"target": {
"file": "fs/exfat/nls.c"
},
"id": "CVE-2025-38206-0fef34fc",
"signature_version": "v1",
"signature_type": "Line"
},
{
"source": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git@13d8de1b6568dcc31a95534ced16bc0c9a67bc15",
"deprecated": false,
"digest": {
"line_hashes": [
"335577595976639138245316047796532771587",
"55537835885452332754232002452218092124"
],
"threshold": 0.9
},
"target": {
"file": "fs/exfat/nls.c"
},
"id": "CVE-2025-38206-3b31f550",
"signature_version": "v1",
"signature_type": "Line"
},
{
"source": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git@d3cef0e7a5c1aa6217c51faa9ce8ecac35d6e1fd",
"deprecated": false,
"digest": {
"line_hashes": [
"335577595976639138245316047796532771587",
"55537835885452332754232002452218092124"
],
"threshold": 0.9
},
"target": {
"file": "fs/exfat/nls.c"
},
"id": "CVE-2025-38206-54a8d64d",
"signature_version": "v1",
"signature_type": "Line"
},
{
"source": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git@13d8de1b6568dcc31a95534ced16bc0c9a67bc15",
"deprecated": false,
"digest": {
"function_hash": "226160876767190123673767391459705220353",
"length": 69.0
},
"target": {
"function": "exfat_free_upcase_table",
"file": "fs/exfat/nls.c"
},
"id": "CVE-2025-38206-5b300d5b",
"signature_version": "v1",
"signature_type": "Function"
},
{
"source": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git@1f3d9724e16d62c7d42c67d6613b8512f2887c22",
"deprecated": false,
"digest": {
"line_hashes": [
"335577595976639138245316047796532771587",
"55537835885452332754232002452218092124"
],
"threshold": 0.9
},
"target": {
"file": "fs/exfat/nls.c"
},
"id": "CVE-2025-38206-a562de89",
"signature_version": "v1",
"signature_type": "Line"
},
{
"source": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git@1f3d9724e16d62c7d42c67d6613b8512f2887c22",
"deprecated": false,
"digest": {
"function_hash": "226160876767190123673767391459705220353",
"length": 69.0
},
"target": {
"function": "exfat_free_upcase_table",
"file": "fs/exfat/nls.c"
},
"id": "CVE-2025-38206-ab6bfca0",
"signature_version": "v1",
"signature_type": "Function"
},
{
"source": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git@d3cef0e7a5c1aa6217c51faa9ce8ecac35d6e1fd",
"deprecated": false,
"digest": {
"function_hash": "226160876767190123673767391459705220353",
"length": 69.0
},
"target": {
"function": "exfat_free_upcase_table",
"file": "fs/exfat/nls.c"
},
"id": "CVE-2025-38206-b5beb713",
"signature_version": "v1",
"signature_type": "Function"
}
]