# CVE-2025-38206

## Summary

- **CVE ID:** CVE-2025-38206
- **Severity:** HIGH
- **CVSS Score:** 7.8 (CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H)
- **CWE:** N/A
- **Published:** Jul 4, 2025
- **Last Modified:** Sep 2, 2026

## Description

In the Linux kernel, the following vulnerability has been resolved:

exfat: fix double free in delayed_free

The double free could happen in the following path.

exfat_create_upcase_table()
        exfat_create_upcase_table() : return error
        exfat_free_upcase_table() : free ->vol_utbl
        exfat_load_default_upcase_table : return error
     exfat_kill_sb()
           delayed_free()
                  exfat_free_upcase_table() <--------- double free
This patch set ->vol_util as NULL after freeing it.

## Affected Products

- Linux — Linux (1acf1a564b6034b5af1e7fb23cb98cb3bb4f6003)
- Linux — Linux (5.7)
- Linux — Linux (0)
- Linux — Linux (5.10.239)
- Linux — Linux (5.15.186)
- Linux — Linux (6.15.4)
- Linux — Linux (6.16)
- Linux — Linux (6.1.187)
- Linux — Linux (6.6.156)
- Linux — Linux (6.12.108)

## References

- [CNA](https://git.kernel.org/stable/c/13d8de1b6568dcc31a95534ced16bc0c9a67bc15)
- [CNA](https://git.kernel.org/stable/c/66e84439ec2af776ce749e8540f8fdd257774152)
- [CNA](https://git.kernel.org/stable/c/d3cef0e7a5c1aa6217c51faa9ce8ecac35d6e1fd)
- [CNA](https://git.kernel.org/stable/c/1f3d9724e16d62c7d42c67d6613b8512f2887c22)
- [CVE](https://lists.debian.org/debian-lts-announce/2025/10/msg00007.html)
- [CNA](https://git.kernel.org/stable/c/ea27703eb0efbadcd45b9949526160ed90536a72)
- [CNA](https://git.kernel.org/stable/c/ac65f76db9b2ff3fbc9e198c0e9aaf81b111b7d0)
- [CNA](https://git.kernel.org/stable/c/29abaf93357f4a7d083cf399d4306999e20db31d)

## Exploitation Prediction (EPSS)

- **EPSS Score:** 0.17%
- **EPSS Percentile:** 6.3

---
_Exported from OnDuty AI Vulnerability Intelligence on 2026-09-18._