Executive brief
A vulnerability exists in the Linux kernel's filesystem buffer handling that could lead to a system crash or unauthorized data access. The issue occurs when the system attempts to read data from certain filesystems, such as NTFS, causing the kernel to access memory that has already been reclaimed. This could result in a denial of service or allow a local attacker to compromise the stability and security of the operating system.
Technical details
A use-after-free (UAF) vulnerability exists in the Linux kernel's buffer head management (fs/buffer.c). The flaw is triggered during synchronous buffer reads (bh_read) when a stack-allocated 'buffer_head' structure is used, specifically observed during NTFS3 filesystem mounts. A race condition exists where the 'wait_on_buffer' call returns and the stack frame is reclaimed before the asynchronous interrupt handler finishes calling 'put_bh(bh)'. This results in a stack-out-of-bounds read/write. The fix involves reordering 'put_bh' to occur before the buffer is unlocked in 'end_buffer_read_sync', ensuring the reference is released while the object is still valid.
Affected products
- Linux Linux Kernel 6.16.0-862.14.0.6.x86_64 and earlier versions
- Siemens SIMATIC CN 4100 V5.0 and earlier versions
- Siemens SIMATIC S7-1500 CPU 1518-4 PN/DP MFP V3.1.6 and earlier versions
Timeline
- 2025-08-11: disclosed: Initial patch submission by Ye Bin
- 2025-08-28: patched: Commits merged into stable trees
- 2025-09-05: advisory: CVE published
References
- https://git.kernel.org/stable/c/03b40bf5d0389ca23ae6857ee25789f0e0b47ce8
- https://git.kernel.org/stable/c/042cf48ecf67f72c8b3846c7fac678f472712ff3
- https://git.kernel.org/stable/c/3169edb8945c295cf89120fc6b2c35cfe3ad4c9e
- https://git.kernel.org/stable/c/70a09115da586bf662c3bae9c0c4a1b99251fad9
- https://git.kernel.org/stable/c/7375f22495e7cd1c5b3b5af9dcc4f6dffe34ce49
- https://git.kernel.org/stable/c/90b5193edb323fefbee0e4e5bc39ed89dcc37719
- https://git.kernel.org/stable/c/c58c6b532b7b69537cfd9ef701c7e37cdcf79dc4