
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2025-39800 is a vulnerability discovered in the Linux kernel's btrfs filesystem component, specifically in the btrfs_copy_root() function. The vulnerability was disclosed on September 15, 2025, affecting multiple Linux distributions and their kernel versions (NVD, Ubuntu).
The vulnerability occurs in the btrfs filesystem when handling extent buffer generation during root copying operations. Specifically, when an unexpected generation for the extent buffer is encountered during btrfs_copy_root() execution, the system only triggers a WARN_ON() without properly aborting the transaction, allowing metadata with unexpected generation to persist (NVD).
The vulnerability allows metadata with unexpected generation values to persist in the btrfs filesystem, potentially leading to filesystem inconsistencies and data integrity issues (NVD).
The fix involves modifying the btrfs_copy_root() function to abort the transaction and return -EUCLEAN when an unexpected generation is encountered, rather than just issuing a warning. This has been implemented in various Linux distribution updates (NVD, Debian).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."