cbcvebase.
CVE-2025-39825
published 2025-09-16

CVE-2025-39825: In the Linux kernel, the following vulnerability has been resolved: smb: client: fix race with concurrent opens in rename(2) Besides sending the rename request…

PriorityP417medium4.7CVSS 3.1
AVLACHPRLUINSUCNINAH
EPSS
0.11%
1.3th percentile
In the Linux kernel, the following vulnerability has been resolved: smb: client: fix race with concurrent opens in rename(2) Besides sending the rename request to the server, the rename process also involves closing any deferred close, waiting for outstanding I/O to complete as well as marking all existing open handles as deleted to prevent them from deferring closes, which increases the race window for potential concurrent opens on the target file. Fix this by unhashing the dentry in advance to prevent any concurrent opens on the target.

Affected

21 ranges
VendorProductVersion rangeFixed in
debiandebian_linux
debianlinux< linux 6.1.153-1 (bookworm)linux 6.1.153-1 (bookworm)
debianlinux-6.1< linux 6.1.153-1 (bookworm)linux 6.1.153-1 (bookworm)
linuxlinux
linuxlinux>= 78c09634f7dc061a3bd09704cdbebb3762a45cdf < c9e7de284da0be5b44dbe79d71573f9f7f9b144cc9e7de284da0be5b44dbe79d71573f9f7f9b144c
linuxlinux>= 78c09634f7dc061a3bd09704cdbebb3762a45cdf < 24b9ed739c8c5b464d983e12cf308982f3ae93c224b9ed739c8c5b464d983e12cf308982f3ae93c2
linuxlinux>= 78c09634f7dc061a3bd09704cdbebb3762a45cdf < c9991af5e09924f6f3b3e6996a5e09f9504b4358c9991af5e09924f6f3b3e6996a5e09f9504b4358
linuxlinux>= 78c09634f7dc061a3bd09704cdbebb3762a45cdf < 289f945acb20b9b54fe4d13895e44aa58965ddb2289f945acb20b9b54fe4d13895e44aa58965ddb2
linuxlinux>= 78c09634f7dc061a3bd09704cdbebb3762a45cdf < d84291fc7453df7881a970716f8256273aca5747d84291fc7453df7881a970716f8256273aca5747
linuxlinux_kernel
linuxlinux_kernel>= 0 < 6.1.153-16.1.153-1
linuxlinux_kernel>= 0 < 6.12.48-16.12.48-1
linuxlinux_kernel>= 0 < 6.16.5-16.16.5-1
linuxlinux_kernel>= 0 < 6.8.0-106.1066.8.0-106.106
linuxlinux_kernel>= 5.13 < 6.1.1506.1.150
linuxlinux_kernel>= 6.13 < 6.16.56.16.5
linuxlinux_kernel>= 6.2 < 6.6.1046.6.104
linuxlinux_kernel>= 6.7 < 6.12.456.12.45
msrcazl3_kernel_6.6.96.2-2_on_azure_linux_3.0
msrccbl2_kernel_5.15.186.1-1_on_cbl_mariner_2.0
ubuntulinux-xilinx

CVSS provenance

nvdv3.14.7MEDIUMCVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H
osv4.7MEDIUM
vendor_ubuntu7.8HIGH
vendor_msrc7.0HIGH
vendor_debian4.7MEDIUM
vendor_redhat4.7MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.