CVE-2025-39691: fs/buffer: fix use-after-free when call bh_read() helper
Published Sep 5, 2025
·Updated
fs/buffer: fix use-after-free when call bhread() helper
Affected Software
19 affected componentsFixes available
Linux Kernel
Microsoft azl3 kernel 6.6.96.2-2
Microsoft azl3 kernel 6.6.96.2-1
Linux Linux kernel>=2.6.13<5.4.297
Linux Linux kernel>=5.5<5.10.241
Linux Linux kernel>=5.11<5.15.190
Linux Linux kernel>=5.16<6.1.149
Linux Linux kernel>=6.2<6.6.103
Linux Linux kernel>=6.7<6.12.44
Linux Linux kernel>=6.13<6.16.4
Linux Linux kernel=2.6.12
Linux Linux kernel=2.6.12-rc2
Linux Linux kernel=2.6.12-rc3
Linux Linux kernel=2.6.12-rc4
Linux Linux kernel=2.6.12-rc5
Linux Linux kernel=6.17-rc1
Linux Linux kernel=6.17-rc2
Debian Debian Linux=11.0
Microsoft cbl2 kernel 5.15.186.1-1
Event History
Sep 5, 2025
CVE Published
via MITRE·05:20 PM
Data Sourced
via MITRE·05:20 PM
DescriptionSeverity
Data Sourced
via NVD·06:15 PM
RemedyDescriptionSeverityWeaknessAffected Software
Sep 7, 2025
Data Sourced
via Microsoft·01:13 AM
DescriptionSeverityWeaknessAffected Software
Updated
via Microsoft·01:13 AM
SeverityAffected Software
Updated
via Microsoft·08:13 AM
SeverityAffected Software
Updated
via Microsoft·08:13 AM
DescriptionSeverity
Frequently Asked Questions
1
What is the severity of CVE-2025-39691?
CVE-2025-39691 has been classified as a high severity vulnerability due to the potential for denial of service.
2
How do I fix CVE-2025-39691?
To fix CVE-2025-39691, update to the latest version of the Linux Kernel that includes the patch for this vulnerability.
3
What type of vulnerability is CVE-2025-39691?
CVE-2025-39691 is a use-after-free vulnerability affecting the Linux kernel's buffer handling functions.
4
Which systems are affected by CVE-2025-39691?
CVE-2025-39691 affects various versions of the Linux kernel used in multiple Linux distributions.
5
When was CVE-2025-39691 reported?
CVE-2025-39691 was reported in 2025 and is part of ongoing security improvements in the Linux kernel.