Junglewise Threat Intelligence

CVE-2025-39723: Linux Kernel netfs NULL pointer dereference in unbuffered write handling

CVE-2025-39723 · Severity: high · CVSS 7.1 · Published 2025-09-05

Technologies: Linux Kernel. Vendors: Linux.

Executive brief

A vulnerability in the Linux kernel's network file system (netfs) component could allow a local user to cause a system crash. The issue occurs when certain file write operations fail, leading the system to incorrectly process memory and result in a 'kernel oops' or crash. This primarily affects systems using network-based storage or specific file-splicing operations.

Technical details

A vulnerability exists in the netfs unbuffered write error handling logic. When all subrequests in an unbuffered write stream fail, the 'stream->transferred' value is not updated and retains its initial LONG_MAX value. This causes 'write_iter()' to return an incorrect, extremely large value instead of an error code. Subsequent calls to 'iter_file_splice_write()' attempt to clean up pipe buffers based on this large value, leading to an out-of-bounds access and a NULL pointer dereference. The fix introduces a validity flag for the transferred value and initializes the counter to zero. Patches are available in stable kernel releases 6.12.44 and 6.16.4.

Affected products

  • Linux Linux Kernel 6.10 to 6.12.43, 6.13 to 6.16.3

Timeline

  • 2025-08-14: patched: Initial fix authored by David Howells
  • 2025-09-05: disclosed: CVE published

References

Related threats