{"dataType":"CVE_RECORD","dataVersion":"5.2","cveMetadata":{"cveId":"CVE-2025-38139","assignerOrgId":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","state":"PUBLISHED","assignerShortName":"Linux","dateReserved":"2025-04-16T04:51:23.987Z","datePublished":"2025-07-03T08:35:41.271Z","dateUpdated":"2026-05-11T21:22:00.930Z"},"containers":{"cna":{"providerMetadata":{"orgId":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","shortName":"Linux","dateUpdated":"2026-05-11T21:22:00.930Z"},"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nnetfs: Fix oops in write-retry from mis-resetting the subreq iterator\n\nFix the resetting of the subrequest iterator in netfs_retry_write_stream()\nto use the iterator-reset function as the iterator may have been shortened\nby a previous retry.  In such a case, the amount of data to be written by\nthe subrequest is not \"subreq->len\" but \"subreq->len -\nsubreq->transferred\".\n\nWithout this, KASAN may see an error in iov_iter_revert():\n\n   BUG: KASAN: slab-out-of-bounds in iov_iter_revert lib/iov_iter.c:633 [inline]\n   BUG: KASAN: slab-out-of-bounds in iov_iter_revert+0x443/0x5a0 lib/iov_iter.c:611\n   Read of size 4 at addr ffff88802912a0b8 by task kworker/u32:7/1147\n\n   CPU: 1 UID: 0 PID: 1147 Comm: kworker/u32:7 Not tainted 6.15.0-rc6-syzkaller-00052-g9f35e33144ae #0 PREEMPT(full)\n   Hardware name: QEMU Standard PC (Q35 + ICH9, 2009), BIOS 1.16.3-debian-1.16.3-2~bpo12+1 04/01/2014\n   Workqueue: events_unbound netfs_write_collection_worker\n   Call Trace:\n    <TASK>\n    __dump_stack lib/dump_stack.c:94 [inline]\n    dump_stack_lvl+0x116/0x1f0 lib/dump_stack.c:120\n    print_address_description mm/kasan/report.c:408 [inline]\n    print_report+0xc3/0x670 mm/kasan/report.c:521\n    kasan_report+0xe0/0x110 mm/kasan/report.c:634\n    iov_iter_revert lib/iov_iter.c:633 [inline]\n    iov_iter_revert+0x443/0x5a0 lib/iov_iter.c:611\n    netfs_retry_write_stream fs/netfs/write_retry.c:44 [inline]\n    netfs_retry_writes+0x166d/0x1a50 fs/netfs/write_retry.c:231\n    netfs_collect_write_results fs/netfs/write_collect.c:352 [inline]\n    netfs_write_collection_worker+0x23fd/0x3830 fs/netfs/write_collect.c:374\n    process_one_work+0x9cf/0x1b70 kernel/workqueue.c:3238\n    process_scheduled_works kernel/workqueue.c:3319 [inline]\n    worker_thread+0x6c8/0xf10 kernel/workqueue.c:3400\n    kthread+0x3c2/0x780 kernel/kthread.c:464\n    ret_from_fork+0x45/0x80 arch/x86/kernel/process.c:153\n    ret_from_fork_asm+0x1a/0x30 arch/x86/entry/entry_64.S:245\n    </TASK>"}],"affected":[{"product":"Linux","vendor":"Linux","defaultStatus":"unaffected","repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","programFiles":["fs/netfs/write_retry.c"],"versions":[{"version":"cd0277ed0c188dd40e7744e89299af7b78831ca4","lessThan":"e0fefe9bc07e6101fdc57abda3644f296c114e31","status":"affected","versionType":"git"},{"version":"cd0277ed0c188dd40e7744e89299af7b78831ca4","lessThan":"bd0edaf99a920b1a9decd773179caacacb61d0fd","status":"affected","versionType":"git"},{"version":"cd0277ed0c188dd40e7744e89299af7b78831ca4","lessThan":"4481f7f2b3df123ec77e828c849138f75cff2bf2","status":"affected","versionType":"git"}]},{"product":"Linux","vendor":"Linux","defaultStatus":"affected","repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","programFiles":["fs/netfs/write_retry.c"],"versions":[{"version":"6.12","status":"affected"},{"version":"0","lessThan":"6.12","status":"unaffected","versionType":"semver"},{"version":"6.12.37","lessThanOrEqual":"6.12.*","status":"unaffected","versionType":"semver"},{"version":"6.15.3","lessThanOrEqual":"6.15.*","status":"unaffected","versionType":"semver"},{"version":"6.16","lessThanOrEqual":"*","status":"unaffected","versionType":"original_commit_for_fix"}]}],"cpeApplicability":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"6.12","versionEndExcluding":"6.12.37"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"6.12","versionEndExcluding":"6.15.3"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"6.12","versionEndExcluding":"6.16"}]}]}],"references":[{"url":"https://git.kernel.org/stable/c/e0fefe9bc07e6101fdc57abda3644f296c114e31"},{"url":"https://git.kernel.org/stable/c/bd0edaf99a920b1a9decd773179caacacb61d0fd"},{"url":"https://git.kernel.org/stable/c/4481f7f2b3df123ec77e828c849138f75cff2bf2"}],"title":"netfs: Fix oops in write-retry from mis-resetting the subreq iterator","x_generator":{"engine":"bippy-1.2.0"}}}}