Junglewise Threat Intelligence

CVE-2025-39835: Linux Kernel XFS null pointer dereference in xattr code

CVE-2025-39835 · Severity: high · CVSS 7.8 · Published 2025-09-16

Technologies: Linux Kernel. Vendors: Linux.

Executive brief

A vulnerability in the Linux kernel's XFS file system could allow a local user to cause a system crash (kernel oops). The issue occurs when the system incorrectly handles certain disk errors during extended attribute (xattr) lookups, leading to a null pointer dereference. This can result in a denial of service or potentially other system instabilities.

Technical details

A vulnerability exists in the XFS file system component of the Linux kernel where ENODATA (ENOATTR) errors returned from disk media are not properly distinguished from 'attribute not found' status codes. In xfs_attr_leaf_get(), an ENODATA error from the disk can result in a NULL buffer pointer (bp). Subsequent calls to xfs_trans_brelse() with this NULL pointer trigger a null pointer dereference (kernel oops). The fix involves remapping ENODATA errors from lower-level IO functions to EIO to ensure they are handled correctly by higher-level XFS functions. This affects kernels from version 5.9 onwards.

Affected products

  • Linux Linux Kernel 5.9 to 5.10.242, 5.11 to 5.15.191, 5.16 to 6.1.150, 6.2 to 6.6.104, 6.7 to 6.12.45, 6.13 to 6.16.5

Timeline

  • 2025-08-22: other: Patch authored by Eric Sandeen
  • 2025-09-16: disclosed: CVE published
  • 2025-09-16: advisory

References

Related threats