Junglewise Threat Intelligence

CVE-2025-39791: Linux Kernel dm-crypt Deadlock and Data Corruption in Zoned Targets

CVE-2025-39791 · Severity: high · CVSS 7.8 · Published 2025-09-11

Technologies: Linux Kernel. Vendors: Linux.

Executive brief

A vulnerability in the Linux kernel's disk encryption component (dm-crypt) can lead to system deadlocks or data corruption when using specific types of storage known as zoned devices. This affects systems that use encrypted storage on modern high-capacity drives that utilize zoned namespaces. An exploit could result in a complete system freeze or the silent corruption of files stored on the encrypted drive, potentially leading to permanent data loss or operational disruption.

Technical details

A vulnerability exists in the dm-crypt target of the Linux kernel when processing write BIOs for zoned devices. The issue stems from BIO splitting logic: when a large write BIO is split into smaller operations to fit internal limits, it can trigger a deadlock during queue freeze operations because the remainder BIO is re-issued from a zone write plug work context that calls blk_queue_enter(). Additionally, splitting zone append operations causes incorrect sector reporting to the issuer, leading to data corruption in file systems like XFS or Btrfs. The fix modifies get_max_request_sectors() to ensure entire BIOs are accepted without splitting for zoned targets and adjusts max_hw_sectors limits to prevent improper fragmentation.

Affected products

  • Linux Linux Kernel 6.10 to 6.12.44

Timeline

  • 2025-06-25: disclosed: Initial patch submission
  • 2025-08-28: patched: Patches committed to stable trees
  • 2025-09-11: advisory: CVE published

References

Related threats