---
id: CVE-2025-39866
title: 'fs: writeback: fix use-after-free in __mark_inode_dirty()'
summary: |-
  In the Linux kernel, the following vulnerability has been resolved:

  fs: writeback: fix use-after-free in __mark_inode_dirty()

  An use-after-free issue occurred when __mark_inode_dirty() get the
  bdi_writeback that was in the progress of …
severity: high
cvss: 7.8
cvssVector: 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H'
cvssSource: cna
vendor: Linux
product: Linux
affected:
  - >-
    Linux >= 0747259d13febfcc838980a63c414c9b920cea6f <
    e2a14bbae5d8bacaa301362744a110e2be40a3a3
  - >-
    Linux >= 0747259d13febfcc838980a63c414c9b920cea6f <
    b187c976111960e6e54a6b1fff724f6e3d39406c
  - >-
    Linux >= 0747259d13febfcc838980a63c414c9b920cea6f <
    1edc2feb9c759a9883dfe81cb5ed231412d8b2e4
  - >-
    Linux >= 0747259d13febfcc838980a63c414c9b920cea6f <
    bf89b1f87c72df79cf76203f71fbf8349cd5c9de
  - >-
    Linux >= 0747259d13febfcc838980a63c414c9b920cea6f <
    e63052921f1b25a836feb1500b841bff7a4a0456
  - >-
    Linux >= 0747259d13febfcc838980a63c414c9b920cea6f <
    c8c14adf80bd1a6e4a1d7ee9c2a816881c26d17a
  - >-
    Linux >= 0747259d13febfcc838980a63c414c9b920cea6f <
    d02d2c98d25793902f65803ab853b592c7a96b29
  - Linux 4.2
exploitAvailable: true
published: '2025-09-19'
updated: '2026-09-08'
sourceUpdated: '2026-09-08T08:42:30.193Z'
source: CVEORG
sourceUrl: 'https://www.cve.org/CVERecord?id=CVE-2025-39866'
references:
  - url: 'https://git.kernel.org/stable/c/e2a14bbae5d8bacaa301362744a110e2be40a3a3'
  - url: 'https://git.kernel.org/stable/c/b187c976111960e6e54a6b1fff724f6e3d39406c'
  - url: 'https://git.kernel.org/stable/c/1edc2feb9c759a9883dfe81cb5ed231412d8b2e4'
  - url: 'https://git.kernel.org/stable/c/bf89b1f87c72df79cf76203f71fbf8349cd5c9de'
  - url: 'https://git.kernel.org/stable/c/e63052921f1b25a836feb1500b841bff7a4a0456'
  - url: 'https://git.kernel.org/stable/c/c8c14adf80bd1a6e4a1d7ee9c2a816881c26d17a'
  - url: 'https://git.kernel.org/stable/c/d02d2c98d25793902f65803ab853b592c7a96b29'
tags:
  - cve.org
  - exploit-available
epss: 0.00307
epssPercentile: 0.20955
exploits:
  github: 1
  githubRepos:
    - 'https://github.com/byteReaper77/CVE-2025-39866'
  checkedAt: '2026-09-26T09:05:33.438Z'
ingestedAt: '2026-09-08T15:33:26.997Z'
---

## Overview

In the Linux kernel, the following vulnerability has been resolved:

fs: writeback: fix use-after-free in __mark_inode_dirty()

An use-after-free issue occurred when __mark_inode_dirty() get the
bdi_writeback that was in the progress of switching.

CPU: 1 PID: 562 Comm: systemd-random- Not tainted 6.6.56-gb4403bd46a8e #1
......
pstate: 60400005 (nZCv daif +PAN -UAO -TCO -DIT -SSBS BTYPE=--)
pc : __mark_inode_dirty+0x124/0x418
lr : __mark_inode_dirty+0x118/0x418
sp : ffffffc08c9dbbc0
........
Call trace:
 __mark_inode_dirty+0x124/0x418
 generic_update_time+0x4c/0x60
 file_modified+0xcc/0xd0
 ext4_buffered_write_iter+0x58/0x124
 ext4_file_write_iter+0x54/0x704
 vfs_write+0x1c0/0x308
 ksys_write+0x74/0x10c
 __arm64_sys_write+0x1c/0x28
 invoke_syscall+0x48/0x114
 el0_svc_common.constprop.0+0xc0/0xe0
 do_el0_svc+0x1c/0x28
 el0_svc+0x40/0xe4
 el0t_64_sync_handler+0x120/0x12c
 el0t_64_sync+0x194/0x198

Root cause is:

systemd-random-seed                         kworker
----------------------------------------------------------------------
___mark_inode_dirty                     inode_switch_wbs_work_fn

  spin_lock(&inode->i_lock);
  inode_attach_wb
  locked_inode_to_wb_and_lock_list
     get inode->i_wb
     spin_unlock(&inode->i_lock);
     spin_lock(&wb->list_lock)
  spin_lock(&inode->i_lock)
  inode_io_list_move_locked
  spin_unlock(&wb->list_lock)
  spin_unlock(&inode->i_lock)
                                    spin_lock(&old_wb->list_lock)
                                      inode_do_switch_wbs
                                        spin_lock(&inode->i_lock)
                                        inode->i_wb = new_wb
                                        spin_unlock(&inode->i_lock)
                                    spin_unlock(&old_wb->list_lock)
                                    wb_put_many(old_wb, nr_switched)
                                      cgwb_release
                                      old wb released
  wb_wakeup_delayed() accesses wb,
  then trigger the use-after-free
  issue

Fix this race condition by holding inode spinlock until
wb_wakeup_delayed() finished.

## Affected

- `Linux >= 0747259d13febfcc838980a63c414c9b920cea6f < e2a14bbae5d8bacaa301362744a110e2be40a3a3`
- `Linux >= 0747259d13febfcc838980a63c414c9b920cea6f < b187c976111960e6e54a6b1fff724f6e3d39406c`
- `Linux >= 0747259d13febfcc838980a63c414c9b920cea6f < 1edc2feb9c759a9883dfe81cb5ed231412d8b2e4`
- `Linux >= 0747259d13febfcc838980a63c414c9b920cea6f < bf89b1f87c72df79cf76203f71fbf8349cd5c9de`
- `Linux >= 0747259d13febfcc838980a63c414c9b920cea6f < e63052921f1b25a836feb1500b841bff7a4a0456`
- `Linux >= 0747259d13febfcc838980a63c414c9b920cea6f < c8c14adf80bd1a6e4a1d7ee9c2a816881c26d17a`
- `Linux >= 0747259d13febfcc838980a63c414c9b920cea6f < d02d2c98d25793902f65803ab853b592c7a96b29`
- `Linux 4.2`

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
