Review reviewHigh

CVE-2025-39866

Linux Linux, SIMATIC CN 4100, SIMATIC S7-1500 CPU 1518-4 PN/DP MFP

In the Linux kernel, the following vulnerability has been resolved: fs: writeback: fix use-after-free in __mark_inode_dirty() An use-after-free issue occurred when __mark_inode_dirty() get the bdi_writeback that was in the progress of switching. CPU: 1 PID: 562 Comm: systemd-random- Not tainted 6.6.56-gb4403bd46a8e #1 ...... pstate: 60400005 (nZCv daif +PAN -UAO -TCO -DIT -SSBS BTYPE=--) pc : __mark_inode_dirty+0x124/0x418 lr : __mark_inode_dirty+0x118/0x418 sp : ffffffc08c9dbbc0 ........ Call trace: __mark_inode_dirty+0x124/0x418 generic_update_time+0x4c/0x60 file_modified+0xcc/0xd0 ext4_b...

CVSS
7.8
EPSS
0.29%
20.8% percentile
CISA KEV
Not listed
Published
2025.09.20
PRIORITY ASSESSMENT

Review review

The CVSS severity warrants an early asset and exposure review.

Known exploitationNot established by KEV
Exploit probability0.29%
Technical severityCVSS 7.8

Vulnerability overview

In the Linux kernel, the following vulnerability has been resolved: fs: writeback: fix use-after-free in __mark_inode_dirty() An use-after-free issue occurred when __mark_inode_dirty() get the bdi_writeback that was in the progress of switching. CPU: 1 PID: 562 Comm: systemd-random- Not tainted 6.6.56-gb4403bd46a8e #1 ...... pstate: 60400005 (nZCv daif +PAN -UAO -TCO -DIT -SSBS BTYPE=--) pc : __mark_inode_dirty+0x124/0x418 lr : __mark_inode_dirty+0x118/0x418 sp : ffffffc08c9dbbc0 ........ Call trace: __mark_inode_dirty+0x124/0x418 generic_update_time+0x4c/0x60 file_modified+0xcc/0xd0 ext4_b...

Affected product and versions

Product
Linux Linux, SIMATIC CN 4100, SIMATIC S7-1500 CPU 1518-4 PN/DP MFP
Affected versions
>= 0747259d13febfcc838980a63c414c9b920cea6f < e2a14bbae5d8bacaa301362744a110e2be40a3a3, >= 0747259d13febfcc838980a63c414c9b920cea6f < b187c976111960e6e54a6b1fff724f6e3d39406c, >= 0747259d13febfcc838980a63c414c9b920cea6f < 1edc2feb9c759a9883dfe81cb5ed231412d8b2e4, >= 0747259d13febfcc838980a63c414c9b920cea6f < bf89b1f87c72df79cf76203f71fbf8349cd5c9de, >= 0747259d13febfcc838980a63c414c9b920cea6f < e63052921f1b25a836feb1500b841bff7a4a0456, >= 0747259d13febfcc838980a63c414c9b920cea6f < c8c14adf80bd1a6e4a1d7ee9c2a816881c26d17a, >= 0747259d13febfcc838980a63c414c9b920cea6f < d02d2c98d25793902f65803ab853b592c7a96b29, >= 4.2, < V5.0, >= V3.1.5, >= V3.1.6, >= 4.2 < 5.10.247, >= 5.11 < 5.15.192, >= 5.16 < 6.1.151, >= 6.2 < 6.6.105, >= 6.7 < 6.12.46, >= 6.13 < 6.16.6, 6.17, 11.0
Fixed versions
5.10.247, 5.15.192, 6.1.151, 6.6.105, 6.12.46, 6.16.6

Recommended response sequence

Confirm exposure before applying a vendor-supported change.

Full remediation guide
  1. 1
    Identify

    Confirm that Linux Linux, SIMATIC CN 4100, SIMATIC S7-1500 CPU 1518-4 PN/DP MFP and an affected version are present.

  2. 2
    Prioritize

    Combine exploitation signals with asset exposure and business criticality.

  3. 3
    Remediate

    Follow the vendor advisory or supported update path and preserve rollback options.

  4. 4
    Verify

    Recheck the version, service health, access paths, and relevant logs.

Technical data

CVSS vector
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
CWE
CWE-416