{
    "dataType": "CVE_RECORD",
    "dataVersion": "5.2",
    "cveMetadata": {
        "cveId": "CVE-2025-38139",
        "assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
        "state": "PUBLISHED",
        "assignerShortName": "Linux",
        "dateReserved": "2025-04-16T04:51:23.987Z",
        "datePublished": "2025-07-03T08:35:41.271Z",
        "dateUpdated": "2026-08-05T11:59:50.138Z"
    },
    "containers": {
        "cna": {
            "providerMetadata": {
                "orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
                "shortName": "Linux",
                "dateUpdated": "2026-08-05T11:59:50.138Z"
            },
            "descriptions": [
                {
                    "lang": "en",
                    "value": "In the Linux kernel, the following vulnerability has been resolved:\n\nnetfs: Fix oops in write-retry from mis-resetting the subreq iterator\n\nFix the resetting of the subrequest iterator in netfs_retry_write_stream()\nto use the iterator-reset function as the iterator may have been shortened\nby a previous retry.  In such a case, the amount of data to be written by\nthe subrequest is not \"subreq->len\" but \"subreq->len -\nsubreq->transferred\".\n\nWithout this, KASAN may see an error in iov_iter_revert():\n\n   BUG: KASAN: slab-out-of-bounds in iov_iter_revert lib/iov_iter.c:633 [inline]\n   BUG: KASAN: slab-out-of-bounds in iov_iter_revert+0x443/0x5a0 lib/iov_iter.c:611\n   Read of size 4 at addr ffff88802912a0b8 by task kworker/u32:7/1147\n\n   CPU: 1 UID: 0 PID: 1147 Comm: kworker/u32:7 Not tainted 6.15.0-rc6-syzkaller-00052-g9f35e33144ae #0 PREEMPT(full)\n   Hardware name: QEMU Standard PC (Q35 + ICH9, 2009), BIOS 1.16.3-debian-1.16.3-2~bpo12+1 04/01/2014\n   Workqueue: events_unbound netfs_write_collection_worker\n   Call Trace:\n    <TASK>\n    __dump_stack lib/dump_stack.c:94 [inline]\n    dump_stack_lvl+0x116/0x1f0 lib/dump_stack.c:120\n    print_address_description mm/kasan/report.c:408 [inline]\n    print_report+0xc3/0x670 mm/kasan/report.c:521\n    kasan_report+0xe0/0x110 mm/kasan/report.c:634\n    iov_iter_revert lib/iov_iter.c:633 [inline]\n    iov_iter_revert+0x443/0x5a0 lib/iov_iter.c:611\n    netfs_retry_write_stream fs/netfs/write_retry.c:44 [inline]\n    netfs_retry_writes+0x166d/0x1a50 fs/netfs/write_retry.c:231\n    netfs_collect_write_results fs/netfs/write_collect.c:352 [inline]\n    netfs_write_collection_worker+0x23fd/0x3830 fs/netfs/write_collect.c:374\n    process_one_work+0x9cf/0x1b70 kernel/workqueue.c:3238\n    process_scheduled_works kernel/workqueue.c:3319 [inline]\n    worker_thread+0x6c8/0xf10 kernel/workqueue.c:3400\n    kthread+0x3c2/0x780 kernel/kthread.c:464\n    ret_from_fork+0x45/0x80 arch/x86/kernel/process.c:153\n    ret_from_fork_asm+0x1a/0x30 arch/x86/entry/entry_64.S:245\n    </TASK>"
                }
            ],
            "metrics": [
                {
                    "cvssV3_1": {
                        "version": "3.1",
                        "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
                        "baseScore": 9.8,
                        "baseSeverity": "CRITICAL"
                    },
                    "scenarios": [
                        {
                            "lang": "en",
                            "value": "AV:N - The trigger is entirely under the control of the remote 9p server, which drives the retry path by reporting short byte counts in its RWRITE replies; the 9p client supports trans=tcp/trans=rdma to a remote peer and the protocol is unauthenticated and unencrypted by default, so an on-path attacker can inject the same replies.\nAC:L - Exploitation is fully deterministic — the server simply answers two consecutive TWRITEs on the same subrequest with a partial count, and the second retry over-reverts the iterator by an attacker-chosen amount; there is no race, timing window, or uncontrollable memory-layout precondition.\nPR:N - The malicious or compromised 9p server (or an on-path attacker on plaintext 9p/TCP) holds no credentials on the victim client, and 9p mounts are typically established with no authentication at all.\nUI:N - No per-instance victim action is needed: on an existing 9p mount, ordinary file writes and background writeback from the kworker reach the retry path, and the server alone decides when to emit the short write that arms it.\nS:U - The out-of-bounds access and the resulting corrupted iterator stay within the kernel's own security authority; no VM, IOMMU, or sandbox boundary is crossed.\nC:H - iov_iter_revert() reads out of bounds backwards off the kvmalloc'd bvec array (or off the head of the folio_queue chain) by an attacker-chosen distance, and the resulting forged bio_vec makes the client transmit memory pointed to by an adjacent-heap page pointer straight to the attacker-controlled server, yielding arbitrary kernel memory disclosure.\nI:H - The corrupted iterator carries bv_page/bv_len values sourced from attacker-groomable adjacent heap memory (or a stale/freed folio_queue), so subsequent I/O submission and page reference get/put operate on arbitrary struct page pointers, giving refcount corruption and a path to control-flow hijack.\nA:H - The bug is a confirmed oops — syzbot reproduced a KASAN slab-out-of-bounds in iov_iter_revert() from netfs_write_collection_worker, and the unbounded backwards walk readily runs off the slab or dereferences a NULL folioq->prev, panicking the kernel."
                        }
                    ]
                }
            ],
            "affected": [
                {
                    "product": "Linux",
                    "vendor": "Linux",
                    "defaultStatus": "unaffected",
                    "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
                    "programFiles": [
                        "fs/netfs/write_retry.c"
                    ],
                    "versions": [
                        {
                            "version": "cd0277ed0c188dd40e7744e89299af7b78831ca4",
                            "lessThan": "e0fefe9bc07e6101fdc57abda3644f296c114e31",
                            "status": "affected",
                            "versionType": "git"
                        },
                        {
                            "version": "cd0277ed0c188dd40e7744e89299af7b78831ca4",
                            "lessThan": "bd0edaf99a920b1a9decd773179caacacb61d0fd",
                            "status": "affected",
                            "versionType": "git"
                        },
                        {
                            "version": "cd0277ed0c188dd40e7744e89299af7b78831ca4",
                            "lessThan": "4481f7f2b3df123ec77e828c849138f75cff2bf2",
                            "status": "affected",
                            "versionType": "git"
                        }
                    ]
                },
                {
                    "product": "Linux",
                    "vendor": "Linux",
                    "defaultStatus": "affected",
                    "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
                    "programFiles": [
                        "fs/netfs/write_retry.c"
                    ],
                    "versions": [
                        {
                            "version": "6.12",
                            "status": "affected"
                        },
                        {
                            "version": "0",
                            "lessThan": "6.12",
                            "status": "unaffected",
                            "versionType": "semver"
                        },
                        {
                            "version": "6.12.37",
                            "lessThanOrEqual": "6.12.*",
                            "status": "unaffected",
                            "versionType": "semver"
                        },
                        {
                            "version": "6.15.3",
                            "lessThanOrEqual": "6.15.*",
                            "status": "unaffected",
                            "versionType": "semver"
                        },
                        {
                            "version": "6.16",
                            "lessThanOrEqual": "*",
                            "status": "unaffected",
                            "versionType": "original_commit_for_fix"
                        }
                    ]
                }
            ],
            "cpeApplicability": [
                {
                    "nodes": [
                        {
                            "operator": "OR",
                            "negate": false,
                            "cpeMatch": [
                                {
                                    "vulnerable": true,
                                    "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                                    "versionStartIncluding": "6.12",
                                    "versionEndExcluding": "6.12.37"
                                },
                                {
                                    "vulnerable": true,
                                    "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                                    "versionStartIncluding": "6.12",
                                    "versionEndExcluding": "6.15.3"
                                },
                                {
                                    "vulnerable": true,
                                    "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                                    "versionStartIncluding": "6.12",
                                    "versionEndExcluding": "6.16"
                                }
                            ]
                        }
                    ]
                }
            ],
            "references": [
                {
                    "url": "https://git.kernel.org/stable/c/e0fefe9bc07e6101fdc57abda3644f296c114e31"
                },
                {
                    "url": "https://git.kernel.org/stable/c/bd0edaf99a920b1a9decd773179caacacb61d0fd"
                },
                {
                    "url": "https://git.kernel.org/stable/c/4481f7f2b3df123ec77e828c849138f75cff2bf2"
                }
            ],
            "title": "netfs: Fix oops in write-retry from mis-resetting the subreq iterator",
            "x_generator": {
                "engine": "bippy-1.2.0"
            }
        }
    }
}