{"id":"UBUNTU-CVE-2025-10823","details":"A vulnerability was found in axboe fio up to 3.41. This affects the function str_buffer_pattern_cb of the file options.c. Performing manipulation results in null pointer dereference. The attack must be initiated from a local position. The exploit has been made public and could be used.","modified":"2026-05-20T16:20:18.639204566Z","published":"2025-09-23T00:15:00Z","upstream":["CVE-2025-10823"],"references":[{"type":"REPORT","url":"https://ubuntu.com/security/CVE-2025-10823"},{"type":"REPORT","url":"https://www.cve.org/CVERecord?id=CVE-2025-10823"},{"type":"REPORT","url":"https://github.com/axboe/fio/issues/1982"},{"type":"REPORT","url":"https://github.com/user-attachments/files/22266964/poc.zip"},{"type":"REPORT","url":"https://vuldb.com/?ctiid.325180"},{"type":"REPORT","url":"https://vuldb.com/?id.325180"},{"type":"REPORT","url":"https://vuldb.com/?submit.654069"}],"affected":[{"package":{"name":"fio","ecosystem":"Ubuntu:14.04:LTS","purl":"pkg:deb/ubuntu/fio?arch=source&distro=trusty"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"}]}],"versions":["2.0.8-2","2.1.3-1"],"ecosystem_specific":{"binaries":[{"binary_name":"fio","binary_version":"2.1.3-1"}],"priority_reason":"local access required"},"database_specific":{"source":"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2025/UBUNTU-CVE-2025-10823.json"}},{"package":{"name":"fio","ecosystem":"Ubuntu:16.04:LTS","purl":"pkg:deb/ubuntu/fio?arch=source&distro=xenial"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"}]}],"versions":["2.1.11-2","2.2.10-1","2.2.10-1ubuntu1"],"ecosystem_specific":{"priority_reason":"local access required","binaries":[{"binary_name":"fio","binary_version":"2.2.10-1ubuntu1"},{"binary_name":"gfio","binary_version":"2.2.10-1ubuntu1"}]},"database_specific":{"source":"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2025/UBUNTU-CVE-2025-10823.json"}},{"package":{"name":"fio","ecosystem":"Ubuntu:18.04:LTS","purl":"pkg:deb/ubuntu/fio?arch=source&distro=bionic"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"}]}],"versions":["2.16-1","3.1-1"],"ecosystem_specific":{"priority_reason":"local access required","binaries":[{"binary_name":"fio","binary_version":"3.1-1"},{"binary_version":"3.1-1","binary_name":"gfio"}]},"database_specific":{"source":"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2025/UBUNTU-CVE-2025-10823.json"}},{"package":{"name":"fio","ecosystem":"Ubuntu:20.04:LTS","purl":"pkg:deb/ubuntu/fio?arch=source&distro=focal"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"}]}],"versions":["3.12-2","3.16-1"],"ecosystem_specific":{"binaries":[{"binary_name":"fio","binary_version":"3.16-1"},{"binary_version":"3.16-1","binary_name":"gfio"}],"priority_reason":"local access required"},"database_specific":{"source":"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2025/UBUNTU-CVE-2025-10823.json"}},{"package":{"name":"fio","ecosystem":"Ubuntu:22.04:LTS","purl":"pkg:deb/ubuntu/fio?arch=source&distro=jammy"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"}]}],"versions":["3.25-2","3.28-1"],"ecosystem_specific":{"priority_reason":"local access required","binaries":[{"binary_version":"3.28-1","binary_name":"fio"},{"binary_name":"gfio","binary_version":"3.28-1"}]},"database_specific":{"source":"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2025/UBUNTU-CVE-2025-10823.json"}},{"package":{"name":"fio","ecosystem":"Ubuntu:24.04:LTS","purl":"pkg:deb/ubuntu/fio?arch=source&distro=noble"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"}]}],"versions":["3.35-2","3.36-1","3.36-1build1","3.36-1build2","3.36-1ubuntu0.1"],"ecosystem_specific":{"binaries":[{"binary_version":"3.36-1ubuntu0.1","binary_name":"fio"},{"binary_version":"3.36-1ubuntu0.1","binary_name":"fio-examples"}],"priority_reason":"local access required"},"database_specific":{"source":"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2025/UBUNTU-CVE-2025-10823.json"}},{"package":{"name":"fio","ecosystem":"Ubuntu:25.10","purl":"pkg:deb/ubuntu/fio?arch=source&distro=questing"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"}]}],"versions":["3.38-1","3.39-1"],"ecosystem_specific":{"binaries":[{"binary_name":"fio","binary_version":"3.39-1"},{"binary_name":"fio-examples","binary_version":"3.39-1"}],"priority_reason":"local access required"},"database_specific":{"source":"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2025/UBUNTU-CVE-2025-10823.json"}},{"package":{"name":"fio","ecosystem":"Ubuntu:26.04:LTS","purl":"pkg:deb/ubuntu/fio?arch=source&distro=resolute"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"}]}],"versions":["3.39-1","3.41-2"],"ecosystem_specific":{"binaries":[{"binary_name":"fio","binary_version":"3.41-2"},{"binary_version":"3.41-2","binary_name":"fio-examples"}],"priority_reason":"local access required"},"database_specific":{"source":"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2025/UBUNTU-CVE-2025-10823.json"}}],"schema_version":"1.7.5","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L"},{"type":"CVSS_V4","score":"CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:P"},{"type":"Ubuntu","score":"low"}]}