CVE-2025-39885
Linux Debian vulnerability analysis and mitigation

Overview

CVE-2025-39885 is a vulnerability discovered in the Linux kernel affecting the OCFS2 filesystem. The issue was disclosed on September 23, 2025, and involves a recursive semaphore deadlock in the fiemap call functionality (NVD, Debian Tracker).

Technical details

The vulnerability occurs when ocfs2fiemap() takes a read lock of the ipallocsem semaphore and calls fiemapfillnextextent() to read the extent list of a running mmap executable. When the user-supplied buffer to hold the fiemap information page faults, it calls ocfs2pagemkwrite() which attempts to take a write lock of the same semaphore. This recursive semaphore condition holds filesystem locks and causes a filesystem hang (NVD).

Impact

The vulnerability can cause a filesystem hang in the OCFS2 filesystem when triggered, potentially leading to system unavailability. The issue affects systems using the OCFS2 filesystem and can be triggered through a specially crafted mmap file (NVD).

Mitigation and workarounds

The fix involves releasing the read semaphore before calling fiemapfillnextextent() in ocfs2fiemap() and ocfs2fiemapinline(). While this creates an unnecessary semaphore lock/unlock on the last extent, it simplifies the error path. Fixed versions are available in Linux kernel 6.12.48-1 for Debian trixie and 6.16.8-1 for Debian sid (Debian Tracker).

Additional resources


SourceThis report was generated using AI

Related Linux Debian vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2025-59343HIGH8.7
  • JavaScriptJavaScript
  • tar-fs
NoYesSep 24, 2025
CVE-2025-60020MEDIUM6.4
  • Linux DebianLinux Debian
  • nncp
NoNoSep 24, 2025
CVE-2025-8869MEDIUM5.9
  • PythonPython
  • rhel8/flatpak-runtime
NoYesSep 24, 2025
CVE-2025-39890N/AN/A
  • Linux DebianLinux Debian
  • linux
NoYesSep 24, 2025
CVE-2025-39889N/AN/A
  • Linux KernelLinux Kernel
  • kernel-rt-64k-modules-partner
NoYesSep 24, 2025

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management