CVE-2025-38218: f2fs: fix to do sanity check on sit_bitmap_size
In the Linux kernel, the following vulnerability has been resolved:
f2fs: fix to do sanity check on sit_bitmap_size
w/ below testcase, resize will generate a corrupted image which
contains inconsistent metadata, so when mounting such image, it
will trigger kernel panic:
touch img
truncate -s $((512*1024*1024*1024)) img
mkfs.f2fs -f img $((256*1024*1024))
resize.f2fs -s -i img -t $((1024*1024*1024))
mount img /mnt/f2fs
------------[ cut here ]------------
kernel BUG at fs/f2fs/segment.h:863!
Oops: invalid opcode: 0000 [#1] SMP PTI
CPU: 11 UID: 0 PID: 3922 Comm: mount Not tainted 6.15.0-rc1+ #191 PREEMPT(voluntary)
Hardware name: QEMU Standard PC (i440FX + PIIX, 1996), BIOS 1.16.3-debian-1.16.3-2 04/01/2014
RIP: 0010:f2fs_ra_meta_pages+0x47c/0x490
Call Trace:
f2fs_build_segment_manager+0x11c3/0x2600
f2fs_fill_super+0xe97/0x2840
mount_bdev+0xf4/0x140
legacy_get_tree+0x2b/0x50
vfs_get_tree+0x29/0xd0
path_mount+0x487/0xaf0
__x64_sys_mount+0x116/0x150
do_syscall_64+0x82/0x190
entry_SYSCALL_64_after_hwframe+0x76/0x7e
RIP: 0033:0x7fdbfde1bcfe
The reaseon is:
sit_i->bitmap_size is 192, so size of sit bitmap is 192*8=1536, at maximum
there are 1536 sit blocks, however MAIN_SEGS is 261893, so that sit_blk_cnt
is 4762, build_sit_entries() -> current_sit_addr() tries to access
out-of-boundary in sit_bitmap at offset from [1536, 4762), once sit_bitmap
and sit_bitmap_mirror is not the same, it will trigger f2fs_bug_on().
Let's add sanity check in f2fs_sanity_check_ckpt() to avoid panic.
Security readout for executives and security teams
Plain-English summary
A malformed F2FS filesystem image can crash a vulnerable Linux kernel when mounted. The issue threatens hosts that use F2FS or process untrusted filesystem images. The supplied evidence demonstrates a kernel panic; it does not establish real-world data theft, modification, or active exploitation.
Executive priority
Prioritize patching systems that mount F2FS media or filesystem images, especially multi-user, removable-media, and image-processing environments. Treat this primarily as a host-crash risk based on available evidence. Validate distribution fixes rather than relying solely on upstream version numbers.
Technical view
F2FS trusted an inconsistent sit_bitmap_size during checkpoint validation. The reported image advertised bitmap capacity for 1,536 SIT blocks while metadata required 4,762, causing an out-of-bounds bitmap access and f2fs_bug_on() kernel panic. The kernel fix adds a sanity check in f2fs_sanity_check_ckpt() to reject inconsistent metadata.
Likely exposure
Exposure is most likely where affected Linux kernels mount malformed or attacker-influenced F2FS filesystems. Systems not using F2FS have lower practical exposure. The bundled version data spans multiple stable kernel lines but is insufficiently structured to determine every distribution-specific vulnerable or fixed package.
Exploitation context
The CVSS 3.1 score is 7.8 with local access, low complexity, low privileges, and no user interaction. The supplied record is not in KEV and provides no evidence of active exploitation. It documents a reproducible kernel panic involving a corrupted filesystem image.
Researcher notes
The demonstrated mismatch permits current_sit_addr() to index beyond the SIT bitmap before a mirror comparison triggers f2fs_bug_on(). Although the CVSS vector assigns high confidentiality, integrity, and availability impacts, the supplied narrative directly demonstrates only a panic. No CWE classification or public exploitation evidence is provided.
Mitigation direction
Install a vendor kernel containing the applicable stable F2FS sanity-check fix.
Check distribution advisories for the fixed package corresponding to each deployed kernel line.
Restrict mounting of untrusted or externally supplied F2FS images until systems are patched.
Reduce unnecessary F2FS support or usage where operationally feasible.
Validation and detection
Inventory Linux kernel versions and identify systems using or capable of mounting F2FS.
Confirm vendor packages include the referenced sit_bitmap_size sanity-check backport.
Review kernel logs for F2FS mount failures, f2fs_build_segment_manager traces, or kernel BUG events.
Validate malformed F2FS metadata is rejected safely in an isolated, non-production environment.
Generated from the cited source records. This long-tail analysis has not been individually reviewed by a named human.
Potential ATT&CK relevance
Conservative CVE-to-ATT&CK context
These mappings and lookup hints may be relevant to the vulnerability behavior, CWE, affected product, or exposure path. Glexia-inferred context is not an official MITRE, ATT&CK, CWE, or CVE Program mapping.
ATT&CK lookup starting points
Use these exact CWE pages and searches to review the Glexia ATT&CK library from this CVE's weakness and description context.
cve · low confidence lookup
CVE-2025-38218 mapping review
Open the CVE-to-ATT&CK bridge for reviewed, inferred, or future official mappings tied to this CVE.
These fields come from the CVE record and ADP containers, not from Glexia's Take. They preserve time-varying source decisions such as CISA SSVC, KEV status, CVSS metrics, and provider references.
1CVSS vectors
3Timeline events
1ADP providers
10Source links
CVSS vector scores
1 official score
We collect every scored CVSS vector available in the official CNA and ADP containers. When more than one version is present, the table keeps the source vectors side by side instead of collapsing them into the highest score.