Junglewise Threat Intelligence

CVE-2025-40205: Linux Kernel Btrfs out-of-bounds write in btrfs_encode_fh

CVE-2025-40205 · Severity: high · CVSS 7.8 · Published 2025-11-12

Technologies: Linux Kernel. Vendors: Linux.

Executive brief

A vulnerability exists in the Linux kernel's Btrfs file system component, which is used for managing data storage. Under specific conditions involving file sharing (NFS), the system may attempt to write more data than a memory buffer can hold. This could lead to memory corruption, potentially allowing a local user to crash the system or gain unauthorized access to data.

Technical details

An out-of-bounds write vulnerability exists in fs/btrfs/export.c within the btrfs_encode_fh() function. The function fails to correctly calculate the required buffer size when a parent inode exists and the root IDs of the parent and inode differ, leading to a write of BTRFS_FID_SIZE_CONNECTABLE_ROOT (40 bytes) into a buffer potentially sized only for BTRFS_FID_SIZE_CONNECTABLE (32 bytes). This results in an 8-byte out-of-bounds write at fid->parent_root_objectid. The vulnerability is reachable via local attackers interacting with file handle encoding, typically in NFS-exported Btrfs volumes. Patches have been released for multiple stable kernel branches including 5.4.y, 5.10.y, 5.15.y, and 6.1.y.

Affected products

  • Linux Linux Kernel 2.6.29 to 6.1.157, 5.4.301, 5.10.246, 5.15.195

Timeline

  • 2025-11-12: advisory: CVE-2025-40205 published
  • 2025-10-19: patched: Fix committed to stable kernel trees

References

Related threats