CVE-2025-39731
Linux Debian vulnerability analysis and mitigation

Overview

CVE-2025-39731 is a vulnerability discovered in the Linux kernel affecting the F2FS (Flash-Friendly File System) implementation. The vulnerability was disclosed on September 7, 2025, and involves an invalid context call to vmunmapram() from the f2fsreleasedecomp_mem() function (NVD).

Technical details

The vulnerability occurs when testing F2FS with xfstests using UFS backed virtual disks, where f2fsreleasedecompmem() calls vmunmapram() from an invalid context. The issue manifests as a sleeping function being called from an invalid context at mm/vmalloc.c:2978, with interrupts disabled and in atomic context. The technical trace shows preemptcount of 1 when 0 was expected, and RCU nest depth of 0 (NVD).

Impact

The vulnerability can lead to kernel warnings and potential system instability when F2FS operations are performed under specific conditions. The issue primarily affects systems using F2FS with UFS backed virtual disks during certain file operations (NVD).

Mitigation and workarounds

A patch has been developed that modifies the intask() check inside f2fsreadendio() to also verify if interrupts are disabled. This ensures that pages are unmapped asynchronously in an interrupt handler, preventing the invalid context call (NVD).

Additional resources


SourceThis report was generated using AI

Related Linux Debian vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2025-39734N/AN/A
  • Linux DebianLinux Debian
  • linux
NoYesSep 07, 2025
CVE-2025-39732N/AN/A
  • Linux KernelLinux Kernel
  • kernel-core
NoYesSep 07, 2025
CVE-2025-39731N/AN/A
  • Linux DebianLinux Debian
  • linux
NoYesSep 07, 2025
CVE-2025-39730N/AN/A
  • Linux KernelLinux Kernel
  • kernel-zfcpdump-modules-core
NoYesSep 07, 2025
CVE-2025-39727N/AN/A
  • Linux KernelLinux Kernel
  • kernel-rt-64k-debug
NoYesSep 07, 2025

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management