NFS: Fix a race when updating an existing write
Published Sep 5, 2025
7.8
HIGHCVSS 3.1
EPSS 0.15%
Description
After nfs_lock_and_join_requests() tests for whether the request is still attached to the mapping, nothing prevents a call to nfs_inode_remove_request() from succeeding until we actually lock the page group. The reason is that whoever called nfs_inode_remove_request() doesn't necessarily have a lock on the page group head.
So in order to avoid races, let's take the page group lock earlier in nfs_lock_and_join_requests(), and hold it across the removal of the request in nfs_inode_remove_request().
Affected products
-
- Version StatusaffectedConstraints
- Version StatusaffectedConstraints
- Version StatusaffectedConstraints
- Version StatusaffectedConstraints
- Version StatusaffectedConstraints
- Version StatusaffectedConstraints
- Version StatusaffectedConstraints
- Version
-
- Version 4.14StatusaffectedConstraints-
- Version 0StatusunaffectedConstraints<4.14
- Version 5.10.242StatusunaffectedConstraints<=5.10.*
- Version 5.15.191StatusunaffectedConstraints<=5.15.*
- Version 6.1.150StatusunaffectedConstraints<=6.1.*
- Version 6.12.44StatusunaffectedConstraints<=6.12.*
- Version 6.16.4StatusunaffectedConstraints<=6.16.*
- Version 6.17StatusunaffectedConstraints<=*
- Version 6.6.104StatusunaffectedConstraints<=6.6.*
- Version
Default status is the baseline for the product, each version can override it (e.g. patched versions marked unaffected).
| Vendor | Product | Default status | Versions | ||||||||||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| Linux | Linux | unaffected |
| ||||||||||||||||||||||||||||||
| Linux | Linux | affected |
|
Configuration 1
- ≥ 4.14 · < 5.10.242
- ≥ 5.11 · < 5.15.191
- ≥ 5.16 · < 6.1.150
- ≥ 6.2 · < 6.6.104
- ≥ 6.7 · < 6.12.44
- ≥ 6.13 · < 6.16.4
- 6.17
- 6.17
Configuration 2
- 11.0
No data.
Red Hat Enterprise Linux 10
kernel-0:6.12.0-124.9.1.el10_1
Fixed · RHSA-2025:21118
Red Hat Enterprise Linux 10
kernel-0:6.12.0-55.41.1.el10_0
Fixed · RHSA-2025:19106
Red Hat Enterprise Linux 8
kernel-0:4.18.0-553.85.1.el8_10
Fixed · RHSA-2025:21917
Red Hat Enterprise Linux 8
kernel-rt-0:4.18.0-553.85.1.rt7.426.el8_10
Fixed · RHSA-2025:21920
Red Hat Enterprise Linux 8.2 Advanced Update Support
kernel-0:4.18.0-193.178.1.el8_2
Fixed · RHSA-2025:23445
Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update Support
kernel-0:4.18.0-305.179.1.el8_4
Fixed · RHSA-2025:22752
Red Hat Enterprise Linux 8.4 Extended Update Support Long-Life Add-On
kernel-0:4.18.0-305.179.1.el8_4
Fixed · RHSA-2025:22752
Red Hat Enterprise Linux 8.6 Advanced Mission Critical Update Support
kernel-0:4.18.0-372.170.1.el8_6
Fixed · RHSA-2025:22006
Red Hat Enterprise Linux 8.6 Telecommunications Update Service
kernel-0:4.18.0-372.170.1.el8_6
Fixed · RHSA-2025:22006
Red Hat Enterprise Linux 8.6 Update Services for SAP Solutions
kernel-0:4.18.0-372.170.1.el8_6
Fixed · RHSA-2025:22006
Red Hat Enterprise Linux 8.8 Telecommunications Update Service
kernel-0:4.18.0-477.122.1.el8_8
Fixed · RHSA-2025:22998
Red Hat Enterprise Linux 8.8 Update Services for SAP Solutions
kernel-0:4.18.0-477.122.1.el8_8
Fixed · RHSA-2025:22998
Red Hat Enterprise Linux 9
kernel-0:5.14.0-611.8.1.el9_7
Fixed · RHSA-2025:21469
Red Hat Enterprise Linux 9
kernel-0:5.14.0-611.8.1.el9_7
Fixed · RHSA-2025:21469
Red Hat Enterprise Linux 9.0 Update Services for SAP Solutions
kernel-0:5.14.0-70.153.1.el9_0
Fixed · RHSA-2025:21091
Red Hat Enterprise Linux 9.0 Update Services for SAP Solutions
kernel-rt-0:5.14.0-70.153.1.rt21.225.el9_0
Fixed · RHSA-2025:21136
Red Hat Enterprise Linux 9.2 Update Services for SAP Solutions
kernel-0:5.14.0-284.146.1.el9_2
Fixed · RHSA-2025:21051
Red Hat Enterprise Linux 9.2 Update Services for SAP Solutions
kernel-rt-0:5.14.0-284.146.1.rt14.431.el9_2
Fixed · RHSA-2025:21128
Red Hat Enterprise Linux 9.4 Extended Update Support
kernel-0:5.14.0-427.100.1.el9_4
Fixed · RHSA-2025:21760
Red Hat Enterprise Linux 9.6 Extended Update Support
kernel-0:5.14.0-570.79.1.el9_6
Fixed · RHSA-2026:0804
Red Hat Enterprise Linux 6
kernel
Out of support scope
Red Hat Enterprise Linux 7
kernel
Not affected
Red Hat Enterprise Linux 7
kernel-rt
Not affected
Red Hat Enterprise Linux 9
kernel-rt
Affected
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat Enterprise Linux 10 | kernel-0:6.12.0-124.9.1.el10_1 | Fixed | RHSA-2025:21118 |
| Red Hat Enterprise Linux 10 | kernel-0:6.12.0-55.41.1.el10_0 | Fixed | RHSA-2025:19106 |
| Red Hat Enterprise Linux 8 | kernel-0:4.18.0-553.85.1.el8_10 | Fixed | RHSA-2025:21917 |
| Red Hat Enterprise Linux 8 | kernel-rt-0:4.18.0-553.85.1.rt7.426.el8_10 | Fixed | RHSA-2025:21920 |
| Red Hat Enterprise Linux 8.2 Advanced Update Support | kernel-0:4.18.0-193.178.1.el8_2 | Fixed | RHSA-2025:23445 |
| Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update Support | kernel-0:4.18.0-305.179.1.el8_4 | Fixed | RHSA-2025:22752 |
| Red Hat Enterprise Linux 8.4 Extended Update Support Long-Life Add-On | kernel-0:4.18.0-305.179.1.el8_4 | Fixed | RHSA-2025:22752 |
| Red Hat Enterprise Linux 8.6 Advanced Mission Critical Update Support | kernel-0:4.18.0-372.170.1.el8_6 | Fixed | RHSA-2025:22006 |
| Red Hat Enterprise Linux 8.6 Telecommunications Update Service | kernel-0:4.18.0-372.170.1.el8_6 | Fixed | RHSA-2025:22006 |
| Red Hat Enterprise Linux 8.6 Update Services for SAP Solutions | kernel-0:4.18.0-372.170.1.el8_6 | Fixed | RHSA-2025:22006 |
| Red Hat Enterprise Linux 8.8 Telecommunications Update Service | kernel-0:4.18.0-477.122.1.el8_8 | Fixed | RHSA-2025:22998 |
| Red Hat Enterprise Linux 8.8 Update Services for SAP Solutions | kernel-0:4.18.0-477.122.1.el8_8 | Fixed | RHSA-2025:22998 |
| Red Hat Enterprise Linux 9 | kernel-0:5.14.0-611.8.1.el9_7 | Fixed | RHSA-2025:21469 |
| Red Hat Enterprise Linux 9 | kernel-0:5.14.0-611.8.1.el9_7 | Fixed | RHSA-2025:21469 |
| Red Hat Enterprise Linux 9.0 Update Services for SAP Solutions | kernel-0:5.14.0-70.153.1.el9_0 | Fixed | RHSA-2025:21091 |
| Red Hat Enterprise Linux 9.0 Update Services for SAP Solutions | kernel-rt-0:5.14.0-70.153.1.rt21.225.el9_0 | Fixed | RHSA-2025:21136 |
| Red Hat Enterprise Linux 9.2 Update Services for SAP Solutions | kernel-0:5.14.0-284.146.1.el9_2 | Fixed | RHSA-2025:21051 |
| Red Hat Enterprise Linux 9.2 Update Services for SAP Solutions | kernel-rt-0:5.14.0-284.146.1.rt14.431.el9_2 | Fixed | RHSA-2025:21128 |
| Red Hat Enterprise Linux 9.4 Extended Update Support | kernel-0:5.14.0-427.100.1.el9_4 | Fixed | RHSA-2025:21760 |
| Red Hat Enterprise Linux 9.6 Extended Update Support | kernel-0:5.14.0-570.79.1.el9_6 | Fixed | RHSA-2026:0804 |
| Red Hat Enterprise Linux 6 | kernel | Out of support scope | n/a |
| Red Hat Enterprise Linux 7 | kernel | Not affected | n/a |
| Red Hat Enterprise Linux 7 | kernel-rt | Not affected | n/a |
| Red Hat Enterprise Linux 9 | kernel-rt | Affected | n/a |
No package ranges for this CVE.
Remediation
Red Hat statement
A race condition in the NFS write path allowed a request to be removed after it was checked but before the page-group lock was taken. The fix acquires the page-group lock earlier and holds it across request removal, preventing use-after-state races. This can be triggered by a client with write access to an export and may lead to a kernel crash (remote DoS). This race condition is difficult to trigger in practice, as it requires several conditions to align (concurrent write activity and timing), and there is no evidence of remote control over memory contents. Therefore the most likely outcome is a denial of service (Availability: High), with Confidentiality and Integrity unaffected.
Red Hat mitigation
To mitigate this issue, prevent module nfs from being loaded. Please see https://access.redhat.com/solutions/41278 for how to blacklist a kernel module to prevent it from loading automatically.
References (17)
- https://access.redhat.com/security/cve/CVE-2025-39697 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=2393481 Issue Tracking
- https://cert-portal.siemens.com/productcert/html/ssa-032379.html
- https://cert-portal.siemens.com/productcert/html/ssa-082556.html
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2025-31528 Advisory
- https://git.kernel.org/stable/c/0ff42a32784e0f2cb46a46da8e9f473538c13e1b Patch
- https://git.kernel.org/stable/c/181feb41f0b268e6288bf9a7b984624d7fe2031d Patch
- https://git.kernel.org/stable/c/202a3432d21ac060629a760fff3b0a39859da3ea Patch
- https://git.kernel.org/stable/c/76d2e3890fb169168c73f2e4f8375c7cc24a765e Patch
- https://git.kernel.org/stable/c/92278ae36935a54e65fef9f8ea8efe7e80481ace Patch
- https://git.kernel.org/stable/c/c32e3c71aaa1c1ba05da88605e2ddd493c58794f Patch
- https://git.kernel.org/stable/c/f230d40147cc37eb3aef4d50e2e2c06ea73d9a77 Patch
- https://lists.debian.org/debian-lts-announce/2025/10/msg00007.html Mailing ListThird Party Advisory
- https://lists.debian.org/debian-lts-announce/2025/10/msg00008.html Mailing ListThird Party Advisory
- https://lore.kernel.org/linux-cve-announce/2025090548-CVE-2025-39697-5284@gregkh/T
- https://nvd.nist.gov/vuln/detail/CVE-2025-39697
- https://www.cve.org/CVERecord?id=CVE-2025-39697
Change history (0)
No recorded changes yet.