Junglewise Threat Intelligence

CVE-2025-39792: Linux Kernel Device Mapper deadlock in zoned device BIO splitting

CVE-2025-39792 · Severity: high · CVSS 7.8 · Published 2025-09-12

Technologies: Linux Kernel. Vendors: Linux.

Executive brief

A vulnerability in the Linux kernel's Device Mapper (DM) component could allow a local user to cause a system deadlock or crash. The issue occurs when the system handles data writes to 'zoned' storage devices, which are specialized high-capacity drives often used in data centers. If an exploit is successful, it could lead to a complete denial of service, impacting the availability of the affected server and any operations relying on that storage.

Technical details

A vulnerability in the Linux kernel Device Mapper (DM) arises from improper BIO (Block I/O) splitting logic for zoned devices. When a zoned DM target requires zone append emulation, it utilizes block layer zone write plugging. Previously, target drivers like dm-crypt and dm-flakey could use dm_accept_partial_bio() to split BIOs, which potentially leads to deadlocks during queue freeze operations or returns invalid written sector values. The fix modifies dm_zone_bio_needs_split() to use bio_needs_zone_write_plugging(), forcing a call to bio_split_to_limits() before the BIO reaches the target's map() function. This ensures large BIOs are split according to device limits (such as BLK_MAX_SEGMENTS) before processing, preventing the deadlock condition. Patches have been released for various stable kernel branches including 6.12.43, 6.15.11, and 6.16.2.

Affected products

  • Linux Linux Kernel 6.10 to 6.12.42, 6.13 to 6.15.10, 6.16 to 6.16.1

Timeline

  • 2025-06-25: patched: Initial patch authored by Damien Le Moal
  • 2025-09-12: disclosed: CVE-2025-39792 published

References

Related threats