{"dataType":"CVE_RECORD","dataVersion":"5.2","cveMetadata":{"cveId":"CVE-2025-39697","assignerOrgId":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","state":"PUBLISHED","assignerShortName":"Linux","dateReserved":"2025-04-16T07:20:57.115Z","datePublished":"2025-09-05T17:21:03.178Z","dateUpdated":"2026-08-05T12:04:38.839Z"},"containers":{"cna":{"providerMetadata":{"orgId":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","shortName":"Linux","dateUpdated":"2026-08-05T12:04:38.839Z"},"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nNFS: Fix a race when updating an existing write\n\nAfter nfs_lock_and_join_requests() tests for whether the request is\nstill attached to the mapping, nothing prevents a call to\nnfs_inode_remove_request() from succeeding until we actually lock the\npage group.\nThe reason is that whoever called nfs_inode_remove_request() doesn't\nnecessarily have a lock on the page group head.\n\nSo in order to avoid races, let's take the page group lock earlier in\nnfs_lock_and_join_requests(), and hold it across the removal of the\nrequest in nfs_inode_remove_request()."}],"metrics":[{"cvssV3_1":{"version":"3.1","vectorString":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","baseScore":7.8,"baseSeverity":"HIGH"},"scenarios":[{"lang":"en","value":"AV:L - The vulnerable code is in the NFS client's buffered-write path and is reached through local `write(2)`/mmap dirtying plus writeback-forcing syscalls (`fsync`, `sync_file_range`, `ftruncate`); a purely remote party cannot create the required local writer, though a malicious NFS server can precisely time the racing removal side via its RPC replies.\nAC:L - The attacker controls both sides of the race — one thread issues overlapping buffered writes to the same folio while another forces writeback/invalidation — and can retry the loop indefinitely with no precondition outside their control; server-induced short writes or errors widen the window further.\nPR:L - Only an unprivileged local account with write access to any file on an NFS mount is required, which is the norm on NFS-backed home directories, HPC scratch, and container/Kubernetes NFS volumes.\nUI:N - The attacker's own process performs all the writes, writeback triggers, and truncation; no action by any other user is needed beyond the NFS mount already existing.\nS:U - The corruption and resulting crash are confined to the kernel's own security authority on the affected host; no VM, IOMMU, or sandbox boundary is crossed.\nC:H - Detaching the folio from NFS's private bookkeeping while requests are still live breaks the writeback-state invariant, allowing mismatched `folio_start/end_writeback` and stale `req->wb_head`/folio references so freed or recycled page contents can be transmitted to the server and read back, and truncated-mapping pointers are dereferenced.\nI:H - Writes acknowledged to userspace are silently discarded — the merged request is detached and freed while the folio's dirty bit is consumed by writeback with no RPC sent — corrupting NFS file data for any process on the client, and kernel request/refcount/`nrequests` state is left inconsistent.\nA:H - The zombie request lets the folio be truncated or reclaimed with `folio->mapping` set to NULL while completion paths unconditionally dereference `folio->mapping->host` (`nfs_page_to_inode`, `nfs_inode_remove_request`, `nfs_folio_end_writeback`), producing a kernel oops, and the `WARN_ON_ONCE` splats panic systems running `panic_on_warn`."}]}],"affected":[{"product":"Linux","vendor":"Linux","defaultStatus":"unaffected","repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","programFiles":["fs/nfs/pagelist.c","fs/nfs/write.c","include/linux/nfs_page.h"],"versions":[{"version":"bd37d6fce184836bd5e7cd90ce40116a4fadaf2a","lessThan":"0ff42a32784e0f2cb46a46da8e9f473538c13e1b","status":"affected","versionType":"git"},{"version":"bd37d6fce184836bd5e7cd90ce40116a4fadaf2a","lessThan":"f230d40147cc37eb3aef4d50e2e2c06ea73d9a77","status":"affected","versionType":"git"},{"version":"bd37d6fce184836bd5e7cd90ce40116a4fadaf2a","lessThan":"c32e3c71aaa1c1ba05da88605e2ddd493c58794f","status":"affected","versionType":"git"},{"version":"bd37d6fce184836bd5e7cd90ce40116a4fadaf2a","lessThan":"181feb41f0b268e6288bf9a7b984624d7fe2031d","status":"affected","versionType":"git"},{"version":"bd37d6fce184836bd5e7cd90ce40116a4fadaf2a","lessThan":"92278ae36935a54e65fef9f8ea8efe7e80481ace","status":"affected","versionType":"git"},{"version":"bd37d6fce184836bd5e7cd90ce40116a4fadaf2a","lessThan":"202a3432d21ac060629a760fff3b0a39859da3ea","status":"affected","versionType":"git"},{"version":"bd37d6fce184836bd5e7cd90ce40116a4fadaf2a","lessThan":"76d2e3890fb169168c73f2e4f8375c7cc24a765e","status":"affected","versionType":"git"}]},{"product":"Linux","vendor":"Linux","defaultStatus":"affected","repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","programFiles":["fs/nfs/pagelist.c","fs/nfs/write.c","include/linux/nfs_page.h"],"versions":[{"version":"4.14","status":"affected"},{"version":"0","lessThan":"4.14","status":"unaffected","versionType":"semver"},{"version":"5.10.242","lessThanOrEqual":"5.10.*","status":"unaffected","versionType":"semver"},{"version":"5.15.191","lessThanOrEqual":"5.15.*","status":"unaffected","versionType":"semver"},{"version":"6.1.150","lessThanOrEqual":"6.1.*","status":"unaffected","versionType":"semver"},{"version":"6.6.104","lessThanOrEqual":"6.6.*","status":"unaffected","versionType":"semver"},{"version":"6.12.44","lessThanOrEqual":"6.12.*","status":"unaffected","versionType":"semver"},{"version":"6.16.4","lessThanOrEqual":"6.16.*","status":"unaffected","versionType":"semver"},{"version":"6.17","lessThanOrEqual":"*","status":"unaffected","versionType":"original_commit_for_fix"}]}],"cpeApplicability":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"4.14","versionEndExcluding":"5.10.242"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"4.14","versionEndExcluding":"5.15.191"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"4.14","versionEndExcluding":"6.1.150"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"4.14","versionEndExcluding":"6.6.104"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"4.14","versionEndExcluding":"6.12.44"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"4.14","versionEndExcluding":"6.16.4"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"4.14","versionEndExcluding":"6.17"}]}]}],"references":[{"url":"https://git.kernel.org/stable/c/0ff42a32784e0f2cb46a46da8e9f473538c13e1b"},{"url":"https://git.kernel.org/stable/c/f230d40147cc37eb3aef4d50e2e2c06ea73d9a77"},{"url":"https://git.kernel.org/stable/c/c32e3c71aaa1c1ba05da88605e2ddd493c58794f"},{"url":"https://git.kernel.org/stable/c/181feb41f0b268e6288bf9a7b984624d7fe2031d"},{"url":"https://git.kernel.org/stable/c/92278ae36935a54e65fef9f8ea8efe7e80481ace"},{"url":"https://git.kernel.org/stable/c/202a3432d21ac060629a760fff3b0a39859da3ea"},{"url":"https://git.kernel.org/stable/c/76d2e3890fb169168c73f2e4f8375c7cc24a765e"}],"title":"NFS: Fix a race when updating an existing write","x_generator":{"engine":"bippy-1.2.0"}},"adp":[{"title":"CVE Program Container","references":[{"url":"https://lists.debian.org/debian-lts-announce/2025/10/msg00008.html"},{"url":"https://lists.debian.org/debian-lts-announce/2025/10/msg00007.html"}],"providerMetadata":{"orgId":"af854a3a-2127-422b-91ae-364da2661108","shortName":"CVE","dateUpdated":"2025-11-03T17:42:28.746Z"}},{"x_adpType":"supplier","providerMetadata":{"orgId":"0b142b55-0307-4c5a-b3c9-f314f3fb7c5e","shortName":"siemens-SADP","dateUpdated":"2026-07-14T12:42:40.704Z"},"affected":[{"vendor":"Siemens","product":"SIMATIC CN 4100","versions":[{"status":"affected","version":"0","lessThan":"V5.0","versionType":"custom"}],"defaultStatus":"unknown"},{"vendor":"Siemens","product":"SIMATIC S7-1500 CPU 1518-4 PN/DP MFP","versions":[{"status":"affected","version":"V3.1.5","lessThan":"*","versionType":"custom"}],"defaultStatus":"unknown"},{"vendor":"Siemens","product":"SIMATIC S7-1500 CPU 1518-4 PN/DP MFP","versions":[{"status":"affected","version":"V3.1.5","lessThan":"*","versionType":"custom"}],"defaultStatus":"unknown"},{"vendor":"Siemens","product":"SIMATIC S7-1500 CPU 1518F-4 PN/DP MFP","versions":[{"status":"affected","version":"V3.1.5","lessThan":"*","versionType":"custom"}],"defaultStatus":"unknown"},{"vendor":"Siemens","product":"SIMATIC S7-1500 CPU 1518F-4 PN/DP MFP","versions":[{"status":"affected","version":"V3.1.5","lessThan":"*","versionType":"custom"}],"defaultStatus":"unknown"},{"vendor":"Siemens","product":"SIPLUS S7-1500 CPU 1518-4 PN/DP MFP","versions":[{"status":"affected","version":"V3.1.5","lessThan":"*","versionType":"custom"}],"defaultStatus":"unknown"}],"references":[{"url":"https://cert-portal.siemens.com/productcert/html/ssa-082556.html"},{"url":"https://cert-portal.siemens.com/productcert/html/ssa-032379.html"}]},{"metrics":[{"other":{"type":"ssvc","content":{"id":"CVE-2025-39697","role":"CISA Coordinator","options":[{"Exploitation":"none"},{"Automatable":"no"},{"Technical Impact":"partial"}],"version":"2.0.3","timestamp":"2026-06-10T20:42:24.236193Z"}}}],"title":"CISA ADP Vulnrichment","providerMetadata":{"orgId":"134c704f-9b21-4f2e-91b3-4a467353bcc0","shortName":"CISA-ADP","dateUpdated":"2026-06-11T18:44:22.767Z"}}]}}