Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2025-39734

18
FAUCET Score

CVE-2025-39734 addresses a deadlock vulnerability in the Linux kernel's NTFS3 filesystem driver, specifically affecting Debian and other Linux distributions. This issue was resolved by reverting a previous commit that removed conditional lock acquisition, which had inadvertently introduced the deadlock. The vulnerability has a CVSS score of 5.5 (Medium), indicating a local attack vector with low attack complexity, requiring low privileges and no user interaction. A successful exploit could lead to a high availability impact, likely causing a denial of service. There is no evidence of active exploitation, and no public exploit code is available on platforms like Metasploit, Nuclei, or ExploitDB. However, the vulnerability has garnered some community discussion and media coverage, suggesting awareness within the cybersecurity community.

Impacted Technologies

VendorProductVersion(s)CPE
>= 5.15.165, < 5.15.190CPE matchmatch criteria
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
>= 6.1.103, < 6.1.148CPE matchmatch criteria
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
>= 6.6.44, < 6.6.102CPE matchmatch criteria
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
>= 6.10.3, < 6.12.42CPE matchmatch criteria
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
>= 6.13, < 6.15.10CPE matchmatch criteria
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*

CVSS Data

CVSS version used by this source: 3.1

5.5MEDIUM

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H

Attack Vector
LOCAL
Attack Complexity
LOW
Privileges Required
LOW
User Interaction
NONE
Scope
UNCHANGED
Confidentiality Impact
NONE
Integrity Impact
NONE
Availability Impact
HIGH
Exploitability Score
1.8
Impact Score
3.6
CvssVersion
3.1

Exploit Intelligence

EPSS Score
0.14%
Probability of exploitation in next 30 days
EPSS Percentile
3.4%
Percentile rank of EPSS score among Peer Group
As of 2026-07-28
Model: v2026.06.15
This CVE's current EPSS score of 0.0014 is in the 22nd percentile among its peer group of 15,940 CVEs.

Social Chatter

No social media mentions found for this CVE.

The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.

Media Mentions

The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Patch Available

Vendor Patches (6)

ubuntupatch availablevia ubuntu_usn
Product: linux-xilinx (noble)Fixed in: 6.8.0-1023.24
ubuntupatch availablevia ubuntu_usn
Product: linux-ibm-6.8 (jammy)Fixed in: 6.8.0-1044.44~22.04.1
ubuntupatch availablevia ubuntu_usn
Product: linux-ibm (noble)Fixed in: 6.8.0-1044.44
ubuntupatch availablevia ubuntu_usn
Product: linux-azure-fips (noble)Fixed in: 6.8.0-1046.52+fips1
ubuntupatch availablevia ubuntu_usn
Product: linux-azure (noble)Fixed in: 6.8.0-1046.52
ubuntupatch availablevia ubuntu_usn
Product: linux-azure-6.8 (jammy)Fixed in: 6.8.0-1051.57~22.04.1

Vendor Advisories (7)

ubuntuUSN-8126-1

Linux kernel (Azure) vulnerabilities

Mar 25, 2026
ubuntuUSN-8074-2

Linux kernel (Azure FIPS) vulnerabilities

Mar 4, 2026
ubuntuUSN-8074-1

Linux kernel (Azure) vulnerabilities

Mar 4, 2026
ubuntuUSN-8052-2

Linux kernel (Xilinx) vulnerabilities

Feb 24, 2026
ubuntuUSN-8028-8

Linux kernel (IBM) vulnerabilities

Feb 24, 2026
microsoft2025-Sep/CVE-2025-39734Moderate

Revert "fs/ntfs3: Replace inode_trylock with inode_lock"

Sep 9, 2025
redhatCVE-2025-39734

kernel: Revert "fs/ntfs3: Replace inode_trylock with inode_lock"

Sep 7, 2025

References

git.kernel.org / stable/c/1903a6c1f2818154f6bc87bceaaecafa92b6ac5c
Patch
git.kernel.org / stable/c/7ce6f83ca9d52c9245b7a017466fc4baa1241b0b
Patch
git.kernel.org / stable/c/a49f0abd8959048af18c6c690b065eb0d65b2d21
Patch
git.kernel.org / stable/c/a936be9b5f51c4d23f66fb673e9068c6b08104a4
Patch
git.kernel.org / stable/c/b356ee013a79e7e3147bfe065de376706c5d2ee9
Patch
git.kernel.org / stable/c/bd20733746263acaaf2a21881665db27ee4303d5
Patch
git.kernel.org / stable/c/bec8109f957a6e193e52d1728799994c8005ca83
Patch
lists.debian.org / debian-lts-announce/2025/10/msg00008.html
Mailing ListThird Party Advisory