CVE-2025-10824

MEDIUM

fio < 3.41 - Use-After-Free in __parse_jobs_ini Function

Title source: llm
STIX 2.1

Description

A vulnerability was determined in axboe fio up to 3.41. This impacts the function __parse_jobs_ini of the file init.c. Executing manipulation can lead to use after free. The attack needs to be launched locally. The exploit has been publicly disclosed and may be utilized.

References (5)

Core 5
Core References
Permissions Required, VDB Entry vdb-entry technical-description
https://vuldb.com/?id.325181
Permissions Required, VDB Entry signature permissions-required
https://vuldb.com/?ctiid.325181
Permissions Required, VDB Entry third-party-advisory
https://vuldb.com/?submit.654072
Issue Tracking issue-tracking
https://github.com/axboe/fio/issues/1981

Scores

CVSS v3 5.3
EPSS 0.0013
EPSS Percentile 3.1%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L

CISA SSVC

Vulnrichment
Exploitation poc
Automatable no
Technical Impact partial

Details

CWE
CWE-119 CWE-416
Status published
Products (42)
axboe/fio 3.0
axboe/fio 3.1
axboe/fio 3.10
axboe/fio 3.11
axboe/fio 3.12
axboe/fio 3.13
axboe/fio 3.14
axboe/fio 3.15
axboe/fio 3.16
axboe/fio 3.17
... and 32 more
Published Sep 23, 2025
Tracked Since Feb 18, 2026