Junglewise Threat Intelligence

CVE-2025-39800: Linux Kernel Btrfs transaction handling error in btrfs_copy_root

CVE-2025-39800 · Severity: high · CVSS 7.8 · Published 2025-09-15

Technologies: Siemens SIMATIC CN 4100, Linux Kernel. Vendors: Siemens, Linux.

Executive brief

A vulnerability in the Linux kernel's Btrfs file system could allow a local user to cause system instability or data corruption. The issue occurs when the system fails to properly handle certain internal data updates, potentially allowing incorrect information to be saved to the disk. This could lead to a complete system crash or the loss of stored files.

Technical details

A logic error in the Btrfs file system's btrfs_copy_root() function fails to abort transactions when an unexpected generation is detected for an extent buffer being cloned. Previously, the kernel would only issue a warning (WARN_ON) and continue, potentially persisting corrupted or inconsistent metadata to disk. An attacker with local access could exploit this to trigger a transaction abort or cause file system inconsistency. The fix ensures that the transaction is properly aborted and returns an -EUCLEAN error when an invalid generation is encountered. Patches have been backported to various stable kernel branches including 6.1, 6.6, 6.12, and 6.16.

Affected products

  • Linux Linux Kernel 2.6.29 to 6.16.4
  • Siemens SIMATIC CN 4100 < V5.0

Timeline

  • 2025-05-19: other: Initial patch authored
  • 2025-09-15: advisory: CVE published

References

Related threats