{ "dataType": "CVE_RECORD", "dataVersion": "5.2", "cveMetadata": { "cveId": "CVE-2025-39697", "assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67", "state": "PUBLISHED", "assignerShortName": "Linux", "dateReserved": "2025-04-16T07:20:57.115Z", "datePublished": "2025-09-05T17:21:03.178Z", "dateUpdated": "2026-08-05T12:04:38.839Z" }, "containers": { "cna": { "providerMetadata": { "orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67", "shortName": "Linux", "dateUpdated": "2026-08-05T12:04:38.839Z" }, "descriptions": [ { "lang": "en", "value": "In the Linux kernel, the following vulnerability has been resolved:\n\nNFS: Fix a race when updating an existing write\n\nAfter nfs_lock_and_join_requests() tests for whether the request is\nstill attached to the mapping, nothing prevents a call to\nnfs_inode_remove_request() from succeeding until we actually lock the\npage group.\nThe reason is that whoever called nfs_inode_remove_request() doesn't\nnecessarily have a lock on the page group head.\n\nSo in order to avoid races, let's take the page group lock earlier in\nnfs_lock_and_join_requests(), and hold it across the removal of the\nrequest in nfs_inode_remove_request()." } ], "metrics": [ { "cvssV3_1": { "version": "3.1", "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H", "baseScore": 7.8, "baseSeverity": "HIGH" }, "scenarios": [ { "lang": "en", "value": "AV:L - The vulnerable code is in the NFS client's buffered-write path and is reached through local `write(2)`/mmap dirtying plus writeback-forcing syscalls (`fsync`, `sync_file_range`, `ftruncate`); a purely remote party cannot create the required local writer, though a malicious NFS server can precisely time the racing removal side via its RPC replies.\nAC:L - The attacker controls both sides of the race — one thread issues overlapping buffered writes to the same folio while another forces writeback/invalidation — and can retry the loop indefinitely with no precondition outside their control; server-induced short writes or errors widen the window further.\nPR:L - Only an unprivileged local account with write access to any file on an NFS mount is required, which is the norm on NFS-backed home directories, HPC scratch, and container/Kubernetes NFS volumes.\nUI:N - The attacker's own process performs all the writes, writeback triggers, and truncation; no action by any other user is needed beyond the NFS mount already existing.\nS:U - The corruption and resulting crash are confined to the kernel's own security authority on the affected host; no VM, IOMMU, or sandbox boundary is crossed.\nC:H - Detaching the folio from NFS's private bookkeeping while requests are still live breaks the writeback-state invariant, allowing mismatched `folio_start/end_writeback` and stale `req->wb_head`/folio references so freed or recycled page contents can be transmitted to the server and read back, and truncated-mapping pointers are dereferenced.\nI:H - Writes acknowledged to userspace are silently discarded — the merged request is detached and freed while the folio's dirty bit is consumed by writeback with no RPC sent — corrupting NFS file data for any process on the client, and kernel request/refcount/`nrequests` state is left inconsistent.\nA:H - The zombie request lets the folio be truncated or reclaimed with `folio->mapping` set to NULL while completion paths unconditionally dereference `folio->mapping->host` (`nfs_page_to_inode`, `nfs_inode_remove_request`, `nfs_folio_end_writeback`), producing a kernel oops, and the `WARN_ON_ONCE` splats panic systems running `panic_on_warn`." } ] } ], "affected": [ { "product": "Linux", "vendor": "Linux", "defaultStatus": "unaffected", "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git", "programFiles": [ "fs/nfs/pagelist.c", "fs/nfs/write.c", "include/linux/nfs_page.h" ], "versions": [ { "version": "bd37d6fce184836bd5e7cd90ce40116a4fadaf2a", "lessThan": "0ff42a32784e0f2cb46a46da8e9f473538c13e1b", "status": "affected", "versionType": "git" }, { "version": "bd37d6fce184836bd5e7cd90ce40116a4fadaf2a", "lessThan": "f230d40147cc37eb3aef4d50e2e2c06ea73d9a77", "status": "affected", "versionType": "git" }, { "version": "bd37d6fce184836bd5e7cd90ce40116a4fadaf2a", "lessThan": "c32e3c71aaa1c1ba05da88605e2ddd493c58794f", "status": "affected", "versionType": "git" }, { "version": "bd37d6fce184836bd5e7cd90ce40116a4fadaf2a", "lessThan": "181feb41f0b268e6288bf9a7b984624d7fe2031d", "status": "affected", "versionType": "git" }, { "version": "bd37d6fce184836bd5e7cd90ce40116a4fadaf2a", "lessThan": "92278ae36935a54e65fef9f8ea8efe7e80481ace", "status": "affected", "versionType": "git" }, { "version": "bd37d6fce184836bd5e7cd90ce40116a4fadaf2a", "lessThan": "202a3432d21ac060629a760fff3b0a39859da3ea", "status": "affected", "versionType": "git" }, { "version": "bd37d6fce184836bd5e7cd90ce40116a4fadaf2a", "lessThan": "76d2e3890fb169168c73f2e4f8375c7cc24a765e", "status": "affected", "versionType": "git" } ] }, { "product": "Linux", "vendor": "Linux", "defaultStatus": "affected", "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git", "programFiles": [ "fs/nfs/pagelist.c", "fs/nfs/write.c", "include/linux/nfs_page.h" ], "versions": [ { "version": "4.14", "status": "affected" }, { "version": "0", "lessThan": "4.14", "status": "unaffected", "versionType": "semver" }, { "version": "5.10.242", "lessThanOrEqual": "5.10.*", "status": "unaffected", "versionType": "semver" }, { "version": "5.15.191", "lessThanOrEqual": "5.15.*", "status": "unaffected", "versionType": "semver" }, { "version": "6.1.150", "lessThanOrEqual": "6.1.*", "status": "unaffected", "versionType": "semver" }, { "version": "6.6.104", "lessThanOrEqual": "6.6.*", "status": "unaffected", "versionType": "semver" }, { "version": "6.12.44", "lessThanOrEqual": "6.12.*", "status": "unaffected", "versionType": "semver" }, { "version": "6.16.4", "lessThanOrEqual": "6.16.*", "status": "unaffected", "versionType": "semver" }, { "version": "6.17", "lessThanOrEqual": "*", "status": "unaffected", "versionType": "original_commit_for_fix" } ] } ], "cpeApplicability": [ { "nodes": [ { "operator": "OR", "negate": false, "cpeMatch": [ { "vulnerable": true, "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*", "versionStartIncluding": "4.14", "versionEndExcluding": "5.10.242" }, { "vulnerable": true, "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*", "versionStartIncluding": "4.14", "versionEndExcluding": "5.15.191" }, { "vulnerable": true, "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*", "versionStartIncluding": "4.14", "versionEndExcluding": "6.1.150" }, { "vulnerable": true, "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*", "versionStartIncluding": "4.14", "versionEndExcluding": "6.6.104" }, { "vulnerable": true, "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*", "versionStartIncluding": "4.14", "versionEndExcluding": "6.12.44" }, { "vulnerable": true, "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*", "versionStartIncluding": "4.14", "versionEndExcluding": "6.16.4" }, { "vulnerable": true, "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*", "versionStartIncluding": "4.14", "versionEndExcluding": "6.17" } ] } ] } ], "references": [ { "url": "https://git.kernel.org/stable/c/0ff42a32784e0f2cb46a46da8e9f473538c13e1b" }, { "url": "https://git.kernel.org/stable/c/f230d40147cc37eb3aef4d50e2e2c06ea73d9a77" }, { "url": "https://git.kernel.org/stable/c/c32e3c71aaa1c1ba05da88605e2ddd493c58794f" }, { "url": "https://git.kernel.org/stable/c/181feb41f0b268e6288bf9a7b984624d7fe2031d" }, { "url": "https://git.kernel.org/stable/c/92278ae36935a54e65fef9f8ea8efe7e80481ace" }, { "url": "https://git.kernel.org/stable/c/202a3432d21ac060629a760fff3b0a39859da3ea" }, { "url": "https://git.kernel.org/stable/c/76d2e3890fb169168c73f2e4f8375c7cc24a765e" } ], "title": "NFS: Fix a race when updating an existing write", "x_generator": { "engine": "bippy-1.2.0" } }, "adp": [ { "title": "CVE Program Container", "references": [ { "url": "https://lists.debian.org/debian-lts-announce/2025/10/msg00008.html" }, { "url": "https://lists.debian.org/debian-lts-announce/2025/10/msg00007.html" } ], "providerMetadata": { "orgId": "af854a3a-2127-422b-91ae-364da2661108", "shortName": "CVE", "dateUpdated": "2025-11-03T17:42:28.746Z" } }, { "x_adpType": "supplier", "providerMetadata": { "orgId": "0b142b55-0307-4c5a-b3c9-f314f3fb7c5e", "shortName": "siemens-SADP", "dateUpdated": "2026-07-14T12:42:40.704Z" }, "affected": [ { "vendor": "Siemens", "product": "SIMATIC CN 4100", "versions": [ { "status": "affected", "version": "0", "lessThan": "V5.0", "versionType": "custom" } ], "defaultStatus": "unknown" }, { "vendor": "Siemens", "product": "SIMATIC S7-1500 CPU 1518-4 PN/DP MFP", "versions": [ { "status": "affected", "version": "V3.1.5", "lessThan": "*", "versionType": "custom" } ], "defaultStatus": "unknown" }, { "vendor": "Siemens", "product": "SIMATIC S7-1500 CPU 1518-4 PN/DP MFP", "versions": [ { "status": "affected", "version": "V3.1.5", "lessThan": "*", "versionType": "custom" } ], "defaultStatus": "unknown" }, { "vendor": "Siemens", "product": "SIMATIC S7-1500 CPU 1518F-4 PN/DP MFP", "versions": [ { "status": "affected", "version": "V3.1.5", "lessThan": "*", "versionType": "custom" } ], "defaultStatus": "unknown" }, { "vendor": "Siemens", "product": "SIMATIC S7-1500 CPU 1518F-4 PN/DP MFP", "versions": [ { "status": "affected", "version": "V3.1.5", "lessThan": "*", "versionType": "custom" } ], "defaultStatus": "unknown" }, { "vendor": "Siemens", "product": "SIPLUS S7-1500 CPU 1518-4 PN/DP MFP", "versions": [ { "status": "affected", "version": "V3.1.5", "lessThan": "*", "versionType": "custom" } ], "defaultStatus": "unknown" } ], "references": [ { "url": "https://cert-portal.siemens.com/productcert/html/ssa-082556.html" }, { "url": "https://cert-portal.siemens.com/productcert/html/ssa-032379.html" } ] }, { "metrics": [ { "other": { "type": "ssvc", "content": { "id": "CVE-2025-39697", "role": "CISA Coordinator", "options": [ { "Exploitation": "none" }, { "Automatable": "no" }, { "Technical Impact": "partial" } ], "version": "2.0.3", "timestamp": "2026-06-10T20:42:24.236193Z" } } } ], "title": "CISA ADP Vulnrichment", "providerMetadata": { "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0", "shortName": "CISA-ADP", "dateUpdated": "2026-06-11T18:44:22.767Z" } } ] } }