CVE-2025-39878

Source
https://cve.org/CVERecord?id=CVE-2025-39878
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2025-39878.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2025-39878
Downstream
Published
2025-09-23T06:00:48Z
Modified
2026-08-12T03:51:27Z
Severity
  • 5.5 (Medium) CVSS_V3 - CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H CVSS Calculator
Summary
ceph: fix crash after fscrypt_encrypt_pagecache_blocks() error
Details

In the Linux kernel, the following vulnerability has been resolved:

ceph: fix crash after fscrypt_encrypt_pagecache_blocks() error

The function move_dirty_folio_in_page_array() was created by commit ce80b76dd327 ("ceph: introduce ceph_process_folio_batch() method") by moving code from ceph_writepages_start() to this function.

This new function is supposed to return an error code which is checked by the caller (now ceph_process_folio_batch()), and on error, the caller invokes redirty_page_for_writepage() and then breaks from the loop.

However, the refactoring commit has gone wrong, and it by accident, it always returns 0 (= success) because it first NULLs the pointer and then returns PTR_ERR(NULL) which is always 0. This means errors are silently ignored, leaving NULL entries in the page array, which may later crash the kernel.

The simple solution is to call PTR_ERR() before clearing the pointer.

Database specific
{
    "cna_assigner": "Linux",
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2025/39xxx/CVE-2025-39878.json"
}
References

Affected packages

Git / git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git

Affected ranges

Type
GIT
Repo
https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git
Events
Introduced
ce80b76dd32764cc914975777e058d4fae4f0ea0
Fixed
dd1616ecbea920d228c56729461ed223cc501425
Fixed
249e0a47cdb46bb9eae65511c569044bd8698d7d

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2025-39878.json"

Linux / Kernel

Package

Name
Kernel

Affected ranges

Type
ECOSYSTEM
Events
Introduced
6.15.0
Fixed
6.16.8

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2025-39878.json"