CVE-2025-39880
A flaw in the Linux kernel's Ceph module allows for improper memory access when handling connection information. This occurs because the system fails to verify which version of a data structure is active before reading from or writing to it.
An official fix is available, so this entry is kept for 30 days and then removed automatically.
Who is affected
Users running the Linux kernel, specifically including version 6.17 and Debian 11.0, who utilize the Ceph module.
Real-world impact
An attacker could potentially cause system instability or memory corruption. Specifically, writing to certain memory locations can lead to serious consequences by overwriting critical connection data.
Why this severity
The critical score reflects that this vulnerability can be exploited remotely without authentication or user interaction, potentially leading to a total loss of confidentiality, integrity, and availability.
What to do about it
- 01Update the Linux kernel to a version that includes the fix for libceph invalid accesses to ceph_connection_v1_info.
NVD-referenced vendor advisory
Timeline
- Sep 23, 2025 · Sep 23, 2025PublishedDisclosed and added to the National Vulnerability Database.
- Jul 30, 2026 · 6h agoAdvisory updatedThe NVD record was last revised.
- Jul 30, 2026 · 3h agoOfficial fix availableA vendor patch or mitigation now exists — see the remediation steps above.
How it’s attacked
References & advisories
- git.kernel.org/stable/c/23538cfbeed87159a5…patch
- git.kernel.org/stable/c/35dbbc3dbf8bccb2d7…patch
- git.kernel.org/stable/c/591ea9c30737663a47…patch
- git.kernel.org/stable/c/6bd8b56899be0b5149…patch
- git.kernel.org/stable/c/cdbc9836c7afadad68…patch
- git.kernel.org/stable/c/ea12ab684f8ae8a6da…patch
- lists.debian.org/debian-lts-announce/2025/10…mailing listthird party advisory