Answer in brief
CVE-2025-38065 records a Unknown severity vulnerability in orangefs: Do not truncate file size. The current sources do not mark it as known exploited. The current feed maps Linux/Linux (generic), Linux/Linux (generic). Check affected ranges and fixed versions before updating.
Analysis pending evidence review
HOL Guard separates source facts from reviewed analysis. See the methodology.
Answer in brief
CVE-2025-38065 records a Unknown severity vulnerability in orangefs: Do not truncate file size. The current sources do not mark it as known exploited. The current feed maps Linux/Linux (generic), Linux/Linux (generic). Check affected ranges and fixed versions before updating.
Analysis pending evidence review
HOL Guard separates source facts from reviewed analysis. See the methodology.
A CVSS score is not reported in the current record. The current sources do not mark it as known exploited. Treat this as a source-backed prioritization signal, not a statement about your environment.
Analysis status
Analysis pending evidence review
Factual feed record only; HOL analysis is not approved for indexing. Read the methodology.
The current feed maps Linux/Linux (generic), Linux/Linux (generic). Check affected ranges and fixed versions before updating.
| Package | Affected range | Fixed version |
|---|---|---|
| Linux/Linuxgeneric | >=f7ab093f74bf638ed98fd1115f3efa17e308bb7f <ceaf195ed285b77791e29016ee6344b3ded609b3 || >=f7ab093f74bf638ed98fd1115f3efa17e308bb7f <341e3a5984cf5761f3dab16029d7e9fb1641d5ff || >=f7ab093f74bf638ed98fd1115f3efa17e308bb7f <5111227d7f1f57f6804666b3abf780a23f44fc1d || >=f7ab093f74bf638ed98fd1115f3efa17e308bb7f <15602508ad2f923e228b9521960b4addcd27d9c4 || >=f7ab093f74bf638ed98fd1115f3efa17e308bb7f <121f0335d91e46369bf55b5da4167d82b099a166 || >=f7ab093f74bf638ed98fd1115f3efa17e308bb7f <cd918ec24168fe08c6aafc077dd3b6d88364c5cf || >=f7ab093f74bf638ed98fd1115f3efa17e308bb7f <2323b806221e6268a4e17711bc72e2fc87c191a3 || >=f7ab093f74bf638ed98fd1115f3efa17e308bb7f <062e8093592fb866b8e016641a8b27feb6ac509d | ceaf195ed285b77791e29016ee6344b3ded609b3, 341e3a5984cf5761f3dab16029d7e9fb1641d5ff, 5111227d7f1f57f6804666b3abf780a23f44fc1d, 15602508ad2f923e228b9521960b4addcd27d9c4, 121f0335d91e46369bf55b5da4167d82b099a166, cd918ec24168fe08c6aafc077dd3b6d88364c5cf, 2323b806221e6268a4e17711bc72e2fc87c191a3, 062e8093592fb866b8e016641a8b27feb6ac509d |
| Linux/Linuxgeneric | 4.6 | Not reported |
Published upstream
Jun 18, 2025
Evidence: source:cvelist:source_dates:source-dates:recordSource modified
Aug 5, 2026
Evidence: source:cvelist:source_dates:source-dates:recordFirst seen by HOL
Aug 5, 2026
In the Linux kernel, the following vulnerability has been resolved: orangefs: Do not truncate file size 'len' is used to store the result of i_size_read(), so making 'len' a size_t results in truncation to 4GiB on 32-bit systems.
Quoted source text, attributed separately from HOL analysis.
A CVSS score is not reported in the current record. The current sources do not mark it as known exploited. Treat this as a source-backed prioritization signal, not a statement about your environment.
Analysis status
Analysis pending evidence review
Factual feed record only; HOL analysis is not approved for indexing. Read the methodology.
The current feed maps Linux/Linux (generic), Linux/Linux (generic). Check affected ranges and fixed versions before updating.
| Package | Affected range | Fixed version |
|---|---|---|
| Linux/Linuxgeneric | >=f7ab093f74bf638ed98fd1115f3efa17e308bb7f <ceaf195ed285b77791e29016ee6344b3ded609b3 || >=f7ab093f74bf638ed98fd1115f3efa17e308bb7f <341e3a5984cf5761f3dab16029d7e9fb1641d5ff || >=f7ab093f74bf638ed98fd1115f3efa17e308bb7f <5111227d7f1f57f6804666b3abf780a23f44fc1d || >=f7ab093f74bf638ed98fd1115f3efa17e308bb7f <15602508ad2f923e228b9521960b4addcd27d9c4 || >=f7ab093f74bf638ed98fd1115f3efa17e308bb7f <121f0335d91e46369bf55b5da4167d82b099a166 || >=f7ab093f74bf638ed98fd1115f3efa17e308bb7f <cd918ec24168fe08c6aafc077dd3b6d88364c5cf || >=f7ab093f74bf638ed98fd1115f3efa17e308bb7f <2323b806221e6268a4e17711bc72e2fc87c191a3 || >=f7ab093f74bf638ed98fd1115f3efa17e308bb7f <062e8093592fb866b8e016641a8b27feb6ac509d | ceaf195ed285b77791e29016ee6344b3ded609b3, 341e3a5984cf5761f3dab16029d7e9fb1641d5ff, 5111227d7f1f57f6804666b3abf780a23f44fc1d, 15602508ad2f923e228b9521960b4addcd27d9c4, 121f0335d91e46369bf55b5da4167d82b099a166, cd918ec24168fe08c6aafc077dd3b6d88364c5cf, 2323b806221e6268a4e17711bc72e2fc87c191a3, 062e8093592fb866b8e016641a8b27feb6ac509d |
| Linux/Linuxgeneric | 4.6 | Not reported |
Published upstream
Jun 18, 2025
Evidence: source:cvelist:source_dates:source-dates:recordSource modified
Aug 5, 2026
Evidence: source:cvelist:source_dates:source-dates:recordFirst seen by HOL
Aug 5, 2026
In the Linux kernel, the following vulnerability has been resolved: orangefs: Do not truncate file size 'len' is used to store the result of i_size_read(), so making 'len' a size_t results in truncation to 4GiB on 32-bit systems.
Quoted source text, attributed separately from HOL analysis.