CVE-2025-39888

Source
https://cve.org/CVERecord?id=CVE-2025-39888
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2025-39888.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2025-39888
Downstream
Published
2025-09-23T06:00:54.156Z
Modified
2026-04-02T12:48:12.207002Z
Severity
  • 7.8 (High) CVSS_V3 - CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H CVSS Calculator
Summary
fuse: Block access to folio overlimit
Details

In the Linux kernel, the following vulnerability has been resolved:

fuse: Block access to folio overlimit

syz reported a slab-out-of-bounds Write in fusedevdo_write.

When the number of bytes to be retrieved is truncated to the upper limit by fc->max_pages and there is an offset, the oob is triggered.

Add a loop termination condition to prevent overruns.

Database specific
{
    "cna_assigner": "Linux",
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2025/39xxx/CVE-2025-39888.json"
}
References

Affected packages

Git / git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git

Affected ranges

Type
GIT
Repo
https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git
Events
Introduced
3568a956932621cafadafc8b75fcf6dc06555105
Fixed
623719227b114d73a2cee45f1b343ced63ce09ec
Fixed
9d81ba6d49a7457784f0b6a71046818b86ec7e44

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2025-39888.json"