SB2025092381 - Improper locking in Linux kernel ocfs2
Published: September 23, 2025
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 1 security vulnerability.
1) Improper locking (CVE-ID: CVE-2025-39885)
The vulnerability allows a local user to perform a denial of service (DoS) attack.
The vulnerability exists due to improper locking within the ocfs2_extent_map_get_blocks(), ocfs2_fiemap_inline() and ocfs2_fiemap() functions in fs/ocfs2/extent_map.c. A local user can perform a denial of service (DoS) attack.
Remediation
Install update from vendor's website.
References
- https://git.kernel.org/stable/c/04100f775c2ea501927f508f17ad824ad1f23c8d
- https://git.kernel.org/stable/c/0709bc11b942870fc0a7be150e42aea42321093a
- https://git.kernel.org/stable/c/1d3c96547ee2ddeaddf8f19a3ef99ea06cc8115e
- https://git.kernel.org/stable/c/36054554772f95d090eb45793faf6aa3c0254b02
- https://git.kernel.org/stable/c/9efcb7a8b97310efed995397941a292cf89fa94f