PT-2025-36317 · Linux+3 · Linux Kernel+3

Published

2025-08-14

·

Updated

2026-04-08

·

CVE-2025-39723

CVSS v3.1

7.8

High

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Linux kernel (affected versions not specified)
Description An issue has been identified in the Linux kernel related to unbuffered write error handling within netfs. When all subrequests in an unbuffered write stream fail, the subrequest collector does not correctly update the transferred value, potentially leading to an incorrect value being returned. This can result in errors, such as an attempt to clean up an excessive amount of pipe bufferage, and ultimately a kernel NULL pointer dereference. The issue was discovered during testing with the generic/750 xfstest against cifs with cache=none, specifically when writes started failing due to insufficient scratch space (ENOSPC).
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Memory Corruption

NULL Pointer Dereference

Weakness Enumeration

Related Identifiers

BDU:2025-15709
CVE-2025-39723
DSA-6008-1
OPENSUSE-SU-2025:20081-1
SUSE-SU-2025:21074-1
SUSE-SU-2025:21139-1
SUSE-SU-2025:21179-1

Affected Products

Astra Linux
Linux Kernel
Red Os
Suse