{"id":"CVE-2025-38660","title":"[ceph] parse_longname(): strrchr() expects NUL-terminated string","summary":"In the Linux kernel, the following vulnerability has been resolved:\n\n[ceph] parse_longname(): strrchr() expects NUL-terminated string\n\n... and parse_longname() is not guaranteed that.  That's the reason\nwhy it uses kmemdup_nul() to build…","severity":"critical","cvss":9.8,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","cvssSource":"cna","vendor":"Linux","product":"Linux","affected":["Linux >= dd66df0053ef84add5e684df517aa9b498342381 < 4b9aee707c4580511983a0998547f3b28514e6a6","Linux >= dd66df0053ef84add5e684df517aa9b498342381 < bb80f7618832d26f7e395f52f82b1dac76223e5f","Linux >= dd66df0053ef84add5e684df517aa9b498342381 < 3145b2b11492d61c512bbc59660bb823bc757f48","Linux >= dd66df0053ef84add5e684df517aa9b498342381 < 493479af8af3ab907f49e99323777d498a4fbd2b","Linux >= dd66df0053ef84add5e684df517aa9b498342381 < 101841c38346f4ca41dc1802c867da990ffb32eb","Linux 6.6"],"published":"2025-08-22","updated":"2026-09-14","sourceUpdated":"2026-09-14T11:58:04.340Z","source":"CVEORG","sourceUrl":"https://www.cve.org/CVERecord?id=CVE-2025-38660","references":[{"url":"https://git.kernel.org/stable/c/4b9aee707c4580511983a0998547f3b28514e6a6"},{"url":"https://git.kernel.org/stable/c/bb80f7618832d26f7e395f52f82b1dac76223e5f"},{"url":"https://git.kernel.org/stable/c/3145b2b11492d61c512bbc59660bb823bc757f48"},{"url":"https://git.kernel.org/stable/c/493479af8af3ab907f49e99323777d498a4fbd2b"},{"url":"https://git.kernel.org/stable/c/101841c38346f4ca41dc1802c867da990ffb32eb"}],"tags":["cve.org"],"epss":0.00389,"epssPercentile":0.32883,"ingestedAt":"2026-09-14T15:23:07.459Z","slug":"CVE-2025-38660","body":"## Overview\n\nIn the Linux kernel, the following vulnerability has been resolved:\n\n[ceph] parse_longname(): strrchr() expects NUL-terminated string\n\n... and parse_longname() is not guaranteed that.  That's the reason\nwhy it uses kmemdup_nul() to build the argument for kstrtou64();\nthe problem is, kstrtou64() is not the only thing that need it.\n\nJust get a NUL-terminated copy of the entire thing and be done\nwith that...\n\n## Affected\n\n- `Linux >= dd66df0053ef84add5e684df517aa9b498342381 < 4b9aee707c4580511983a0998547f3b28514e6a6`\n- `Linux >= dd66df0053ef84add5e684df517aa9b498342381 < bb80f7618832d26f7e395f52f82b1dac76223e5f`\n- `Linux >= dd66df0053ef84add5e684df517aa9b498342381 < 3145b2b11492d61c512bbc59660bb823bc757f48`\n- `Linux >= dd66df0053ef84add5e684df517aa9b498342381 < 493479af8af3ab907f49e99323777d498a4fbd2b`\n- `Linux >= dd66df0053ef84add5e684df517aa9b498342381 < 101841c38346f4ca41dc1802c867da990ffb32eb`\n- `Linux 6.6`\n\n## Remediation\n\nRefer to the linked advisories for vendor-supplied fixes and affected version ranges.","depth":"midnight","depthScore":54,"depthScoreParts":{"impact":53.9,"likelihood":0.1,"exploitation":0,"ransomware":0},"changes":[]}