---
id: CVE-2025-38660
title: '[ceph] parse_longname(): strrchr() expects NUL-terminated string'
summary: |-
  In the Linux kernel, the following vulnerability has been resolved:

  [ceph] parse_longname(): strrchr() expects NUL-terminated string

  ... and parse_longname() is not guaranteed that.  That's the reason
  why it uses kmemdup_nul() to build…
severity: critical
cvss: 9.8
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'
cvssSource: cna
vendor: Linux
product: Linux
affected:
  - >-
    Linux >= dd66df0053ef84add5e684df517aa9b498342381 <
    4b9aee707c4580511983a0998547f3b28514e6a6
  - >-
    Linux >= dd66df0053ef84add5e684df517aa9b498342381 <
    bb80f7618832d26f7e395f52f82b1dac76223e5f
  - >-
    Linux >= dd66df0053ef84add5e684df517aa9b498342381 <
    3145b2b11492d61c512bbc59660bb823bc757f48
  - >-
    Linux >= dd66df0053ef84add5e684df517aa9b498342381 <
    493479af8af3ab907f49e99323777d498a4fbd2b
  - >-
    Linux >= dd66df0053ef84add5e684df517aa9b498342381 <
    101841c38346f4ca41dc1802c867da990ffb32eb
  - Linux 6.6
published: '2025-08-22'
updated: '2026-09-14'
sourceUpdated: '2026-09-14T11:58:04.340Z'
source: CVEORG
sourceUrl: 'https://www.cve.org/CVERecord?id=CVE-2025-38660'
references:
  - url: 'https://git.kernel.org/stable/c/4b9aee707c4580511983a0998547f3b28514e6a6'
  - url: 'https://git.kernel.org/stable/c/bb80f7618832d26f7e395f52f82b1dac76223e5f'
  - url: 'https://git.kernel.org/stable/c/3145b2b11492d61c512bbc59660bb823bc757f48'
  - url: 'https://git.kernel.org/stable/c/493479af8af3ab907f49e99323777d498a4fbd2b'
  - url: 'https://git.kernel.org/stable/c/101841c38346f4ca41dc1802c867da990ffb32eb'
tags:
  - cve.org
epss: 0.00389
epssPercentile: 0.30253
ingestedAt: '2026-09-14T15:23:07.459Z'
---

## Overview

In the Linux kernel, the following vulnerability has been resolved:

[ceph] parse_longname(): strrchr() expects NUL-terminated string

... and parse_longname() is not guaranteed that.  That's the reason
why it uses kmemdup_nul() to build the argument for kstrtou64();
the problem is, kstrtou64() is not the only thing that need it.

Just get a NUL-terminated copy of the entire thing and be done
with that...

## Affected

- `Linux >= dd66df0053ef84add5e684df517aa9b498342381 < 4b9aee707c4580511983a0998547f3b28514e6a6`
- `Linux >= dd66df0053ef84add5e684df517aa9b498342381 < bb80f7618832d26f7e395f52f82b1dac76223e5f`
- `Linux >= dd66df0053ef84add5e684df517aa9b498342381 < 3145b2b11492d61c512bbc59660bb823bc757f48`
- `Linux >= dd66df0053ef84add5e684df517aa9b498342381 < 493479af8af3ab907f49e99323777d498a4fbd2b`
- `Linux >= dd66df0053ef84add5e684df517aa9b498342381 < 101841c38346f4ca41dc1802c867da990ffb32eb`
- `Linux 6.6`

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
