CVE-2025-39691: fs/buffer: fix use-after-free when call bh_read() helper
In the Linux kernel, the following vulnerability has been resolved:
fs/buffer: fix use-after-free when call bh_read() helper
There's issue as follows:
BUG: KASAN: stack-out-of-bounds in end_buffer_read_sync+0xe3/0x110
Read of size 8 at addr ffffc9000168f7f8 by task swapper/3/0
CPU: 3 UID: 0 PID: 0 Comm: swapper/3 Not tainted 6.16.0-862.14.0.6.x86_64
Hardware name: QEMU Standard PC (i440FX + PIIX, 1996)
Call Trace:
<IRQ>
dump_stack_lvl+0x55/0x70
print_address_description.constprop.0+0x2c/0x390
print_report+0xb4/0x270
kasan_report+0xb8/0xf0
end_buffer_read_sync+0xe3/0x110
end_bio_bh_io_sync+0x56/0x80
blk_update_request+0x30a/0x720
scsi_end_request+0x51/0x2b0
scsi_io_completion+0xe3/0x480
? scsi_device_unbusy+0x11e/0x160
blk_complete_reqs+0x7b/0x90
handle_softirqs+0xef/0x370
irq_exit_rcu+0xa5/0xd0
sysvec_apic_timer_interrupt+0x6e/0x90
</IRQ>
Above issue happens when do ntfs3 filesystem mount, issue may happens
as follows:
mount IRQ
ntfs_fill_super
read_cache_page
do_read_cache_folio
filemap_read_folio
mpage_read_folio
do_mpage_readpage
ntfs_get_block_vbo
bh_read
submit_bh
wait_on_buffer(bh);
blk_complete_reqs
scsi_io_completion
scsi_end_request
blk_update_request
end_bio_bh_io_sync
end_buffer_read_sync
__end_buffer_read_notouch
unlock_buffer
wait_on_buffer(bh);--> return will return to caller
put_bh
--> trigger stack-out-of-bounds
In the mpage_read_folio() function, the stack variable 'map_bh' is
passed to ntfs_get_block_vbo(). Once unlock_buffer() unlocks and
wait_on_buffer() returns to continue processing, the stack variable
is likely to be reclaimed. Consequently, during the end_buffer_read_sync()
process, calling put_bh() may result in stack overrun.
If the bh is not allocated on the stack, it belongs to a folio. Freeing
a buffer head which belongs to a folio is done by drop_buffers() which
will fail to free buffers which are still locked. So it is safe to call
put_bh() before __end_buffer_read_notouch().
Security readout for executives and security teams
Plain-English summary
A Linux kernel memory-safety flaw can occur during filesystem reads, demonstrated while mounting an NTFS3 filesystem. A timing race may access a buffer after its stack storage is no longer valid, potentially crashing the system or enabling broader local compromise. The supplied CVSS score is 7.8, but the sources do not establish real-world exploitation.
Executive priority
Treat as a high-priority kernel update for affected multi-user or filesystem-processing systems. Immediate emergency action is less clearly justified because exploitation is local and no active exploitation is documented. Accelerate remediation where untrusted users, removable media, uploaded disk images, or automated filesystem mounting increase access to the vulnerable path.
Technical view
The flaw involves bh_read(), wait_on_buffer(), and asynchronous completion through end_buffer_read_sync(). During mpage_read_folio(), a stack-backed buffer_head may become invalid before the completion path calls put_bh(), causing an out-of-bounds or use-after-free access. The kernel fix changes operation ordering so put_bh() occurs before the buffer is unlocked.
Likely exposure
Exposure requires an affected Linux kernel and local interaction with the relevant filesystem I/O path. The report reproduced the issue during an NTFS3 mount. Exact distribution exposure cannot be determined solely from upstream version data; vendor backports may change whether a particular kernel package is vulnerable.
Exploitation context
The CVSS vector indicates local access, low complexity, low privileges, and no user interaction, with potential confidentiality, integrity, and availability impact. The bundle marks this CVE as absent from KEV and provides no evidence of active exploitation or a public exploit. Practical exploitability beyond the reported KASAN failure remains unconfirmed.
Researcher notes
The supplied affected-version list mixes release numbers and commit identifiers and should not be treated as a definitive package matrix. The described trigger involves a race between wait_on_buffer() returning and asynchronous completion using stack-backed map_bh. Assess vendor backports and configuration-specific reachability; the sources do not prove reliable code execution.
Mitigation direction
Upgrade to a vendor-supported kernel containing the applicable upstream fix or backport.
Review Debian and appliance-vendor advisories for fixed package versions.
Restrict untrusted users from mounting or supplying filesystems until remediation is confirmed.
Prioritize exposed multi-user systems where local users can reach filesystem operations.
Validation and detection
Record each system's running kernel and distribution package version.
Compare packages against vendor advisories and their fixed-version information.
Confirm the vendor kernel includes the relevant upstream fix or documented backport.
Test representative NTFS3 mount workflows safely after updating.
Monitor kernel logs for KASAN reports, crashes, or buffer-read anomalies.
Generated from the cited source records. This long-tail analysis has not been individually reviewed by a named human.
Potential ATT&CK relevance
Conservative CVE-to-ATT&CK context
These mappings and lookup hints may be relevant to the vulnerability behavior, CWE, affected product, or exposure path. Glexia-inferred context is not an official MITRE, ATT&CK, CWE, or CVE Program mapping.
ATT&CK lookup starting points
Use these exact CWE pages and searches to review the Glexia ATT&CK library from this CVE's weakness and description context.
cve · low confidence lookup
CVE-2025-39691 mapping review
Open the CVE-to-ATT&CK bridge for reviewed, inferred, or future official mappings tied to this CVE.
These fields come from the CVE record and ADP containers, not from Glexia's Take. They preserve time-varying source decisions such as CISA SSVC, KEV status, CVSS metrics, and provider references.
1CVSS vectors
3Timeline events
2ADP providers
13Source links
CVSS vector scores
1 official score
We collect every scored CVSS vector available in the official CNA and ADP containers. When more than one version is present, the table keeps the source vectors side by side instead of collapsing them into the highest score.