Junglewise Threat Intelligence

CVE-2025-39738: Linux Kernel Btrfs transaction abort in subvolume relocation

CVE-2025-39738 · Severity: high · CVSS 7.3 · Published 2025-09-11

Technologies: Siemens SIMATIC CN 4100, Linux Kernel. Vendors: Siemens, Linux.

Executive brief

A vulnerability in the Linux kernel's Btrfs file system could allow a local user to cause a system crash or data integrity issues. The problem occurs when the system attempts to reorganize (relocate) data in subvolumes that were previously partially deleted but not fully cleaned up. This can lead to a transaction abort, resulting in a denial of service or potential file system errors.

Technical details

A vulnerability in the Btrfs file system's relocation logic occurs when a subvolume is in a partially dropped state (non-zero drop_progress) but lacks a corresponding orphan item. This state, often caused by older kernel bugs, leads to a transaction abort (-117) during 'btrfs_run_delayed_refs' because the system attempts to insert extent items that no longer have valid backreferences in the extent tree. The fix introduces a check in 'create_reloc_root' to reject relocation for any subvolume with a non-zero drop_progress key, returning -EUCLEAN instead of allowing a transaction abort. This prevents local users from triggering a kernel warning and file system shutdown via standard balance operations on affected volumes.

Affected products

  • Linux Linux Kernel 5.15+
  • Siemens SIMATIC CN 4100 before V5.0

Timeline

  • 2025-07-25: patched: Initial patch by Qu Wenruo
  • 2025-09-11: disclosed: CVE published

References

Related threats