Junglewise Threat Intelligence

CVE-2025-39759: Linux Kernel Btrfs use-after-free in qgroup quota management

CVE-2025-39759 · Severity: high · CVSS 7 · Published 2025-09-11

Technologies: Linux Kernel. Vendors: Linux.

Executive brief

A vulnerability exists in the Linux kernel's Btrfs file system when managing disk quotas. A race condition between disabling quotas and rescanning them can lead to a system crash or potential unauthorized data access. This issue primarily affects local users on systems utilizing Btrfs with quota features enabled.

Technical details

A race condition exists between btrfs_quota_disable() and btrfs_ioctl_quota_rescan() in the Btrfs implementation. When quotas are disabled, the kernel may begin freeing qgroup records from the fs_info->qgroup_tree rbtree without holding the necessary qgroup_lock. Simultaneously, a rescan task may attempt to iterate through the same tree while holding the lock, leading to a use-after-free (UAF) scenario. The vulnerability is triggered because btrfs_quota_disable() fails to wait for a rescan task that has started but not yet set the 'running' flag. The fix involves ensuring the qgroup_lock is held during configuration cleanup and verifying quota status before starting rescan workers.

Affected products

  • Linux Linux Kernel 3.12 to 6.1.149, 6.2 to 6.6.103, 6.7 to 6.12.44, 6.13 to 6.15.11, 6.16 to 6.16.2

Timeline

  • 2025-09-11: disclosed
  • 2025-09-11: advisory
  • 2025-08-20: patched: Initial patch committed to stable tree

References

Related threats