CVE-2025-39819
Linux Kernel vulnerability analysis and mitigation

Overview

CVE-2025-39819 is a vulnerability discovered in the Linux kernel's SMB filesystem implementation, specifically in the smb2_compound_op function. The vulnerability was disclosed on September 16, 2025, affecting the Linux kernel's file system components (NVD).

Technical details

The vulnerability stems from an inconsistent update of refcount in the smb2_compound_op function. The issue occurs when the function fails to properly handle reference counting for the cfile object during memory allocation failures (-ENOMEM errors). According to the documentation, the reference to cfile should be dropped after calling this function, but one specific control flow path failed to maintain this requirement (NVD).

Impact

The inconsistent refcount update could lead to resource leaks in the system. This occurs because existing callers would not handle refcount update of cfile if -ENOMEM is returned, potentially causing system resources to be improperly managed (NVD).

Mitigation and workarounds

The vulnerability has been patched by adding an extra goto label "out" to ensure cleanup logic is always respected. The fix ensures that when allocation of vars fails, the cleanup logic is properly executed. Since -ENOMEM is not a recoverable error according to the is_replayable_error function, the replay logic is bypassed (NVD). For Debian systems, the fix has been included in version 6.1.153-1 for the oldstable distribution (bookworm) (Debian Security).

Additional resources


SourceThis report was generated using AI

Related Linux Kernel vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2025-40343MEDIUM6.4
  • Linux KernelLinux Kernel
  • linux-riscv
NoYesDec 09, 2025
CVE-2025-40342MEDIUM6.4
  • Linux KernelLinux Kernel
  • linux-azure-5.4
NoYesDec 09, 2025
CVE-2025-40341MEDIUM5.1
  • Linux KernelLinux Kernel
  • kernel-debug-uki-virt-addons
NoYesDec 09, 2025
CVE-2025-40345N/AN/A
  • Linux KernelLinux Kernel
  • bpftool
NoYesDec 12, 2025
CVE-2025-40344N/AN/A
  • Linux KernelLinux Kernel
  • rtla
NoYesDec 09, 2025

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management