{ "dataType": "CVE_RECORD", "dataVersion": "5.2", "cveMetadata": { "cveId": "CVE-2025-38139", "assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67", "state": "PUBLISHED", "assignerShortName": "Linux", "dateReserved": "2025-04-16T04:51:23.987Z", "datePublished": "2025-07-03T08:35:41.271Z", "dateUpdated": "2026-08-05T11:59:50.138Z" }, "containers": { "cna": { "providerMetadata": { "orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67", "shortName": "Linux", "dateUpdated": "2026-08-05T11:59:50.138Z" }, "descriptions": [ { "lang": "en", "value": "In the Linux kernel, the following vulnerability has been resolved:\n\nnetfs: Fix oops in write-retry from mis-resetting the subreq iterator\n\nFix the resetting of the subrequest iterator in netfs_retry_write_stream()\nto use the iterator-reset function as the iterator may have been shortened\nby a previous retry. In such a case, the amount of data to be written by\nthe subrequest is not \"subreq->len\" but \"subreq->len -\nsubreq->transferred\".\n\nWithout this, KASAN may see an error in iov_iter_revert():\n\n BUG: KASAN: slab-out-of-bounds in iov_iter_revert lib/iov_iter.c:633 [inline]\n BUG: KASAN: slab-out-of-bounds in iov_iter_revert+0x443/0x5a0 lib/iov_iter.c:611\n Read of size 4 at addr ffff88802912a0b8 by task kworker/u32:7/1147\n\n CPU: 1 UID: 0 PID: 1147 Comm: kworker/u32:7 Not tainted 6.15.0-rc6-syzkaller-00052-g9f35e33144ae #0 PREEMPT(full)\n Hardware name: QEMU Standard PC (Q35 + ICH9, 2009), BIOS 1.16.3-debian-1.16.3-2~bpo12+1 04/01/2014\n Workqueue: events_unbound netfs_write_collection_worker\n Call Trace:\n \n __dump_stack lib/dump_stack.c:94 [inline]\n dump_stack_lvl+0x116/0x1f0 lib/dump_stack.c:120\n print_address_description mm/kasan/report.c:408 [inline]\n print_report+0xc3/0x670 mm/kasan/report.c:521\n kasan_report+0xe0/0x110 mm/kasan/report.c:634\n iov_iter_revert lib/iov_iter.c:633 [inline]\n iov_iter_revert+0x443/0x5a0 lib/iov_iter.c:611\n netfs_retry_write_stream fs/netfs/write_retry.c:44 [inline]\n netfs_retry_writes+0x166d/0x1a50 fs/netfs/write_retry.c:231\n netfs_collect_write_results fs/netfs/write_collect.c:352 [inline]\n netfs_write_collection_worker+0x23fd/0x3830 fs/netfs/write_collect.c:374\n process_one_work+0x9cf/0x1b70 kernel/workqueue.c:3238\n process_scheduled_works kernel/workqueue.c:3319 [inline]\n worker_thread+0x6c8/0xf10 kernel/workqueue.c:3400\n kthread+0x3c2/0x780 kernel/kthread.c:464\n ret_from_fork+0x45/0x80 arch/x86/kernel/process.c:153\n ret_from_fork_asm+0x1a/0x30 arch/x86/entry/entry_64.S:245\n " } ], "metrics": [ { "cvssV3_1": { "version": "3.1", "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H", "baseScore": 9.8, "baseSeverity": "CRITICAL" }, "scenarios": [ { "lang": "en", "value": "AV:N - The trigger is entirely under the control of the remote 9p server, which drives the retry path by reporting short byte counts in its RWRITE replies; the 9p client supports trans=tcp/trans=rdma to a remote peer and the protocol is unauthenticated and unencrypted by default, so an on-path attacker can inject the same replies.\nAC:L - Exploitation is fully deterministic — the server simply answers two consecutive TWRITEs on the same subrequest with a partial count, and the second retry over-reverts the iterator by an attacker-chosen amount; there is no race, timing window, or uncontrollable memory-layout precondition.\nPR:N - The malicious or compromised 9p server (or an on-path attacker on plaintext 9p/TCP) holds no credentials on the victim client, and 9p mounts are typically established with no authentication at all.\nUI:N - No per-instance victim action is needed: on an existing 9p mount, ordinary file writes and background writeback from the kworker reach the retry path, and the server alone decides when to emit the short write that arms it.\nS:U - The out-of-bounds access and the resulting corrupted iterator stay within the kernel's own security authority; no VM, IOMMU, or sandbox boundary is crossed.\nC:H - iov_iter_revert() reads out of bounds backwards off the kvmalloc'd bvec array (or off the head of the folio_queue chain) by an attacker-chosen distance, and the resulting forged bio_vec makes the client transmit memory pointed to by an adjacent-heap page pointer straight to the attacker-controlled server, yielding arbitrary kernel memory disclosure.\nI:H - The corrupted iterator carries bv_page/bv_len values sourced from attacker-groomable adjacent heap memory (or a stale/freed folio_queue), so subsequent I/O submission and page reference get/put operate on arbitrary struct page pointers, giving refcount corruption and a path to control-flow hijack.\nA:H - The bug is a confirmed oops — syzbot reproduced a KASAN slab-out-of-bounds in iov_iter_revert() from netfs_write_collection_worker, and the unbounded backwards walk readily runs off the slab or dereferences a NULL folioq->prev, panicking the kernel." } ] } ], "affected": [ { "product": "Linux", "vendor": "Linux", "defaultStatus": "unaffected", "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git", "programFiles": [ "fs/netfs/write_retry.c" ], "versions": [ { "version": "cd0277ed0c188dd40e7744e89299af7b78831ca4", "lessThan": "e0fefe9bc07e6101fdc57abda3644f296c114e31", "status": "affected", "versionType": "git" }, { "version": "cd0277ed0c188dd40e7744e89299af7b78831ca4", "lessThan": "bd0edaf99a920b1a9decd773179caacacb61d0fd", "status": "affected", "versionType": "git" }, { "version": "cd0277ed0c188dd40e7744e89299af7b78831ca4", "lessThan": "4481f7f2b3df123ec77e828c849138f75cff2bf2", "status": "affected", "versionType": "git" } ] }, { "product": "Linux", "vendor": "Linux", "defaultStatus": "affected", "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git", "programFiles": [ "fs/netfs/write_retry.c" ], "versions": [ { "version": "6.12", "status": "affected" }, { "version": "0", "lessThan": "6.12", "status": "unaffected", "versionType": "semver" }, { "version": "6.12.37", "lessThanOrEqual": "6.12.*", "status": "unaffected", "versionType": "semver" }, { "version": "6.15.3", "lessThanOrEqual": "6.15.*", "status": "unaffected", "versionType": "semver" }, { "version": "6.16", "lessThanOrEqual": "*", "status": "unaffected", "versionType": "original_commit_for_fix" } ] } ], "cpeApplicability": [ { "nodes": [ { "operator": "OR", "negate": false, "cpeMatch": [ { "vulnerable": true, "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*", "versionStartIncluding": "6.12", "versionEndExcluding": "6.12.37" }, { "vulnerable": true, "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*", "versionStartIncluding": "6.12", "versionEndExcluding": "6.15.3" }, { "vulnerable": true, "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*", "versionStartIncluding": "6.12", "versionEndExcluding": "6.16" } ] } ] } ], "references": [ { "url": "https://git.kernel.org/stable/c/e0fefe9bc07e6101fdc57abda3644f296c114e31" }, { "url": "https://git.kernel.org/stable/c/bd0edaf99a920b1a9decd773179caacacb61d0fd" }, { "url": "https://git.kernel.org/stable/c/4481f7f2b3df123ec77e828c849138f75cff2bf2" } ], "title": "netfs: Fix oops in write-retry from mis-resetting the subreq iterator", "x_generator": { "engine": "bippy-1.2.0" } } } }