{"id":"CVE-2025-10823","summary":"axboe fio options.c str_buffer_pattern_cb null pointer dereference","details":"A vulnerability was found in axboe fio up to 3.41. This affects the function str_buffer_pattern_cb of the file options.c. Performing manipulation results in null pointer dereference. The attack must be initiated from a local position. The exploit has been made public and could be used.","modified":"2026-08-12T03:51:16.371519810Z","published":"2025-09-22T23:32:10.940Z","database_specific":{"cwe_ids":["CWE-404","CWE-476"],"osv_generated_from":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2025/10xxx/CVE-2025-10823.json","cna_assigner":"VulDB"},"references":[{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2025/10xxx/CVE-2025-10823.json"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2025-10823"},{"type":"ADVISORY","url":"https://vuldb.com/?id.325180"},{"type":"ADVISORY","url":"https://vuldb.com/?submit.654069"},{"type":"REPORT","url":"https://github.com/axboe/fio/issues/1982"},{"type":"REPORT","url":"https://vuldb.com/?ctiid.325180"},{"type":"EVIDENCE","url":"https://github.com/user-attachments/files/22266964/poc.zip"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/axboe/fio","events":[{"introduced":"bdadbb83ba3611a09888600830b8539bf3d19794"},{"last_affected":"ed675d3477a70a42d2e757b713f6c7125a27cdca"}],"database_specific":{"extracted_events":[{"introduced":"3.0"},{"last_affected":"3.0"},{"introduced":"3.1"},{"last_affected":"3.1"},{"introduced":"3.2"},{"last_affected":"3.2"},{"introduced":"3.3"},{"last_affected":"3.3"},{"introduced":"3.4"},{"last_affected":"3.4"},{"introduced":"3.5"},{"last_affected":"3.5"},{"introduced":"3.6"},{"last_affected":"3.6"},{"introduced":"3.7"},{"last_affected":"3.7"},{"introduced":"3.8"},{"last_affected":"3.8"},{"introduced":"3.9"},{"last_affected":"3.9"},{"introduced":"3.10"},{"last_affected":"3.10"},{"introduced":"3.11"},{"last_affected":"3.11"},{"introduced":"3.12"},{"last_affected":"3.12"},{"introduced":"3.13"},{"last_affected":"3.13"},{"introduced":"3.14"},{"last_affected":"3.14"},{"introduced":"3.15"},{"last_affected":"3.15"},{"introduced":"3.16"},{"last_affected":"3.16"},{"introduced":"3.17"},{"last_affected":"3.17"},{"introduced":"3.18"},{"last_affected":"3.18"},{"introduced":"3.19"},{"last_affected":"3.19"},{"introduced":"3.20"},{"last_affected":"3.20"},{"introduced":"3.21"},{"last_affected":"3.21"},{"introduced":"3.22"},{"last_affected":"3.22"},{"introduced":"3.23"},{"last_affected":"3.23"},{"introduced":"3.24"},{"last_affected":"3.24"},{"introduced":"3.25"},{"last_affected":"3.25"},{"introduced":"3.26"},{"last_affected":"3.26"},{"introduced":"3.27"},{"last_affected":"3.27"},{"introduced":"3.28"},{"last_affected":"3.28"},{"introduced":"3.29"},{"last_affected":"3.29"},{"introduced":"3.30"},{"last_affected":"3.30"},{"introduced":"3.31"},{"last_affected":"3.31"},{"introduced":"3.32"},{"last_affected":"3.32"},{"introduced":"3.33"},{"last_affected":"3.33"},{"introduced":"3.34"},{"last_affected":"3.34"},{"introduced":"3.35"},{"last_affected":"3.35"},{"introduced":"3.36"},{"last_affected":"3.36"},{"introduced":"3.37"},{"last_affected":"3.37"},{"introduced":"3.38"},{"last_affected":"3.38"},{"introduced":"3.39"},{"last_affected":"3.39"},{"introduced":"3.40"},{"last_affected":"3.40"},{"introduced":"3.41"},{"last_affected":"3.41"}],"source":"AFFECTED_FIELD"}}],"versions":["3.0","3.1","3.10","3.11","3.12","3.13","3.14","3.15","3.16","3.17","3.18","3.19","3.2","3.20","3.21","3.22","3.23","3.24","3.25","3.26","3.27","3.28","3.29","3.3","3.30","3.31","3.32","3.33","3.34","3.35","3.36","3.37","3.38","3.39","3.4","3.40","3.41","3.5","3.6","3.7","3.8","3.9","fio-3.41","fio-3.40","fio-3.39","fio-3.38","fio-3.37","fio-3.36","fio-3.35","fio-3.34","fio-3.33","fio-3.32","fio-3.31","test-tag-2022-08-09-2","test-tag-2022-08-09","fio-3.30","fio-3.29","fio-3.16","fio-3.28","fio-3.27","fio-3.26","fio-3.25","fio-3.24","fio-3.23","fio-3.22","fio-3.21","fio-3.20","fio-3.19","fio-3.18","fio-3.17","fio-3.15","fio-3.14","fio-3.13","fio-3.12","fio-3.11","fio-3.10","fio-3.9","fio-3.8","fio-3.7","fio-3.6","fio-3.5","fio-3.4","fio-3.3","fio-3.2","fio-3.1","fio-3.0"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2025-10823.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V4","score":"CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:P"}]}