CVE-2025-39912
published 2025-10-01CVE-2025-39912: In the Linux kernel, the following vulnerability has been resolved: nfs/localio: restore creds before releasing pageio data Otherwise if the nfsd filecache…
PriorityP419medium5.5CVSS 3.1
AVLACLPRLUINSUCNINAH
EPSS
0.13%
3.3th percentile
In the Linux kernel, the following vulnerability has been resolved:
nfs/localio: restore creds before releasing pageio data
Otherwise if the nfsd filecache code releases the nfsd_file
immediately, it can trigger the BUG_ON(cred == current->cred) in
__put_cred() when it puts the nfsd_file->nf_file->f-cred.
Affected
10 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | linux | < linux 6.16.8-1 (forky) | linux 6.16.8-1 (forky) |
| linux | linux | — | — |
| linux | linux | >= b9f5dd57f4a52990963eeb1f1b58d00f717ece69 < 57c1bb02b4fc8eec6eb01736e7fad26dffacf18c | 57c1bb02b4fc8eec6eb01736e7fad26dffacf18c |
| linux | linux | >= b9f5dd57f4a52990963eeb1f1b58d00f717ece69 < c250be1d75bf80dc5ab46f0b434b746c1868a1ea | c250be1d75bf80dc5ab46f0b434b746c1868a1ea |
| linux | linux | >= b9f5dd57f4a52990963eeb1f1b58d00f717ece69 < 992203a1fba51b025c60ec0c8b0d9223343dea95 | 992203a1fba51b025c60ec0c8b0d9223343dea95 |
| linux | linux_kernel | — | — |
| linux | linux_kernel | >= 0 < 6.12.48-1 | 6.12.48-1 |
| linux | linux_kernel | >= 0 < 6.16.8-1 | 6.16.8-1 |
| linux | linux_kernel | >= 6.12 < 6.12.48 | 6.12.48 |
| linux | linux_kernel | >= 6.13 < 6.16.8 | 6.16.8 |
CVSS provenance
nvdv3.15.5MEDIUMCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
osv5.5MEDIUM
vendor_debian5.5LOW
vendor_redhat5.5MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-9qxq-33m2-8r47: In the Linux kernel, the following vulnerability has been resolved:
nfs/localio: restore creds before releasing pageio data
Otherwise if the nfsd fi
ghsa_unreviewed·2025-10-01
CVE-2025-39912 [MEDIUM] GHSA-9qxq-33m2-8r47: In the Linux kernel, the following vulnerability has been resolved:
nfs/localio: restore creds before releasing pageio data
Otherwise if the nfsd fi
In the Linux kernel, the following vulnerability has been resolved:
nfs/localio: restore creds before releasing pageio data
Otherwise if the nfsd filecache code releases the nfsd_file
immediately, it can trigger the BUG_ON(cred == current->cred) in
__put_cred() when it puts the nfsd_file->nf_file->f-cred.
OSV
CVE-2025-39912: In the Linux kernel, the following vulnerability has been resolved: nfs/localio: restore creds before releasing pageio data Otherwise if the nfsd file
osv·2025-10-01·CVSS 5.5
CVE-2025-39912 [MEDIUM] CVE-2025-39912: In the Linux kernel, the following vulnerability has been resolved: nfs/localio: restore creds before releasing pageio data Otherwise if the nfsd file
In the Linux kernel, the following vulnerability has been resolved: nfs/localio: restore creds before releasing pageio data Otherwise if the nfsd filecache code releases the nfsd_file immediately, it can trigger the BUG_ON(cred == current->cred) in __put_cred() when it puts the nfsd_file->nf_file->f-cred.
Red Hat
kernel: nfs/localio: restore creds before releasing pageio data
vendor_redhat·2025-10-01·CVSS 5.5
CVE-2025-39912 [MEDIUM] CWE-672 kernel: nfs/localio: restore creds before releasing pageio data
kernel: nfs/localio: restore creds before releasing pageio data
In the Linux kernel, the following vulnerability has been resolved:
nfs/localio: restore creds before releasing pageio data
Otherwise if the nfsd filecache code releases the nfsd_file
immediately, it can trigger the BUG_ON(cred == current->cred) in
__put_cred() when it puts the nfsd_file->nf_file->f-cred.
Statement: A race in the NFS local I/O path caused credentials to be restored after pageio release, potentially triggering a BUG_ON() in __put_cred(). The issue could lead to a local kernel crash (DoS) during NFS read/write operations.
Package: kernel (Red Hat Enterprise Linux 10) - Fix deferred
Package: kernel (Red Hat Enterprise Linux 6) - Not affected
Package: kernel (Red Hat Enterprise Linux 7) - Not affected
Packag
Debian
CVE-2025-39912: linux - In the Linux kernel, the following vulnerability has been resolved: nfs/localio...
vendor_debian·2025·CVSS 5.5
CVE-2025-39912 [MEDIUM] CVE-2025-39912: linux - In the Linux kernel, the following vulnerability has been resolved: nfs/localio...
In the Linux kernel, the following vulnerability has been resolved: nfs/localio: restore creds before releasing pageio data Otherwise if the nfsd filecache code releases the nfsd_file immediately, it can trigger the BUG_ON(cred == current->cred) in __put_cred() when it puts the nfsd_file->nf_file->f-cred.
Scope: local
bookworm: resolved
bullseye: resolved
forky: resolved (fixed in 6.16.8-1)
sid: resolved (fixed in 6.16.8-1)
trixie: resolved (fixed in 6.12.48-1)
No detection rules found.
No public exploits indexed.
2025-10-01
Published