Home / Security / Advisories / NTAP-20260925-0005
NTAP-20260925-0005 — CVE-2025-38627 Linux Kernel Vulnerability in NetApp Products
Published 2026-09-25 · Updated 2026-09-30 · Status: Interim · Exploitation: Public · Severity: HIGH 7.8 · ONTAP affected: Yes
Product family: Baseboard management controllers · Active IQ Unified Manager · Brocade SAN firmware · ONTAP · Other NetApp products · NetApp Console / BlueXP · SolidFire / NetApp HCI · SnapCenter | ONTAP-relevant | highest CVSS: 7.8
CVEs in this advisory
- CVE-2025-38627 — HIGH · CVSS 7.8 · site index
What the CVE records say
CVE-2025-38627 — In the Linux kernel, the following vulnerability has been resolved: f2fs: compress: fix UAF of f2fs_inode_info in f2fs_free_dic The decompress_io_ctx may be released asynchronously after I/O completion. If this file is deleted immediately after read, and the kworker of processing post_read_wq has not been executed yet due to high workloads, It is possible that the inode(f2fs_inode_info) is evicted and freed before it is used f2fs_free_dic. The UAF case as below: Thread A Thread B - f2fs_decompress_end_io - f2fs_put_dic - queue_work add free_dic work to post_read_wq - do_unlink - iput - evict - call_rcu This file is deleted after read. Thread C kworker to process post_read_wq - rcu_do_batch - f2fs_free_inode - kmem_cache_free inode is freed by rcu - process_scheduled_works - f2fs_late_free_dic - f2fs_free_dic - f2fs_release_decomp_mem read (dic->inode)->i_compress_algorithm This patch store compress_algorithm and sbi in dic to avoid inode UAF. In addition, the previous solution is deprecated in [1] may cause system hang. [1] https://lore.kernel.org/all/c36ab955-c8db-4a8b-a9d0-f07b5f426c3f@kernel.org
Impact
Successful exploitation of this vulnerability could lead to disclosure of sensitive information, addition or modification of data or Denial of Service (DoS).
Affected products
- AFF Baseboard Management Controller (BMC) - A700s
- Active IQ Unified Manager for VMware vSphere
- Brocade Fabric Operating System Firmware
- Cloud Volumes ONTAP Mediator
- FAS/AFF BIOS - A900/9500
- FAS/AFF Baseboard Management Controller (BMC) - A250/500f/C250
- NetApp Console Agent OVA
- NetApp HCI Baseboard Management Controller (BMC) - H610S
- ONTAP tools for VMware vSphere 10
- SnapCenter Plug-in for VMware vSphere
References
What to do
- Check the affected products listed above against the official advisory's affected-versions table — that is where the exact ONTAP 9 release, ONTAP tool, or management product versions are named.
- If affected and a fixed release exists, plan the upgrade — see the ONTAP upgrade runbook.
- If exploitation is listed as "active", treat remediation as urgent and review exposure (management LIFs, ONTAP S3, SnapMirror endpoints).
- Harden in parallel: security hardening baseline and ransomware protection on ONTAP.
Related reading
- Common ONTAP problems (FAQ) — plain-language symptoms and fixes
- ONTAP security hardening — baseline lockdown guidance
- Ransomware protection on ONTAP — SnapLock, SnapMirror vaulting, Anomaly Detection
- ONTAP error messages index — EMS/WAFL/NFS/SnapMirror messages
- Every NetApp advisory published in 2026