Upstream Linux kernel maintainers patched three vulnerabilities reported by researchers, including two NULL pointer dereferences reachable by unprivileged users and a long-standing Btrfs memory corruption issue. CVE-2025-40072 affects fanotify mount-namespace monitoring introduced in Linux 6.16, where do_fanotify_mark() dereferenced the return value of mnt_ns_from_dentry() without verifying it was non-NULL, allowing a kernel crash and denial of service; the fix landed in 6.17.3 and 6.18-rc1. CVE-2025-39950 affects the TCP stack when TCP-AO is combined with TCP_REPAIR, causing tcp_ao_finish_connect() to dereference a NULL skb during connect() and crash the kernel.
A third fix, CVE-2025-40205, addresses a potential 8-byte out-of-bounds write in Btrfs btrfs_encode_fh() that could occur when parent and inode root IDs differ and the function reports a smaller buffer requirement than it later writes. Kernel discussions said the flaw had effectively persisted for about 17 years, with an earlier latent memory-corruption concern in the same area dating back to 2010; the final patch corrected size calculations, added bounds validation, and was marked for stable kernels back to 3.0+. Researchers said the Btrfs issue may be difficult to trigger in practice, but all three bugs were fixed upstream and highlighted as kernel stability and memory-safety risks.

See affected versions and whether adversaries are exploiting it.
9 events from the most recent confirmed update back to the earliest known activity.
A Linux kernel CVE announcement assigned CVE-2025-40205 to the Btrfs btrfs_encode_fh() out-of-bounds write issue and documented fixes across stable branches, including 5.4.301, 5.10.246, 5.15.195, 6.1.157, 6.6.113, 6.12.54, 6.17.4, and 6.18-rc1. The advisory recommended updating to the latest stable kernel rather than cherry-picking individual commits.
A Linux kernel CVE announcement assigned CVE-2025-40072 to the fanotify NULL dereference issue and documented that it was fixed in Linux 6.17.3 and 6.18-rc1. The advisory recommended updating to the latest stable kernel rather than cherry-picking individual commits.
Allele Security published details on three Linux kernel vulnerabilities it reported: fanotify NULL dereference CVE-2025-40072, TCP NULL dereference CVE-2025-39950, and a potential Btrfs out-of-bounds write CVE-2025-40205. The post said all three fixes had already been merged upstream.
David Sterba committed a Linux kernel patch fixing a potential 8-byte out-of-bounds write in Btrfs btrfs_encode_fh() by correcting size calculations and validating *max_len before writing. The commit marked the fix for stable kernels back to 3.0+.
Jakub Kicinski committed a Linux kernel fix for a NULL pointer dereference in tcp_ao_finish_connect() when TCP-AO is used with TCP_REPAIR during connect(). The patch adds a NULL check for skb before accessing tcp_hdr(skb)->seq.
A Linux kernel commit added a NULL check in do_fanotify_mark() before dereferencing the result of mnt_ns_from_dentry(), preventing crashes in the FSNOTIFY_OBJ_TYPE_MNTNS path. This upstream fix is the change later associated with CVE-2025-40072.
Jan Beulich submitted a patch to fix a latent memory corruption issue in btrfs_encode_fh() in Btrfs, adding a bounds check before writing parent_root_objectid. The mailing-list post shows the issue was recognized as early as October 2010.
In a mailing-list reply, David Sterba acknowledged Anderson Nascimento's Btrfs out-of-bounds fix, said the bug appeared to be 17 years old, and noted the patch had not actually been queued as believed. He said he would add it back to the for-next branch.
The Linux kernel CVE announcement states the fanotify flaw later tracked as CVE-2025-40072 was introduced in Linux kernel 6.16 by commit 58f5fbeb367ff6f30a2448b2cad70f70b2de4b06. The bug stems from dereferencing the return value of mnt_ns_from_dentry() without checking for NULL.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See whether adversaries are exploiting this yet, and where the affected versions run in your environment.
11 references tracked. Mallory keeps watching after this page renders.
kernel.org
Open sourcelore.kernel.org
Open sourcelore.kernel.org
Open sourceallelesecurity.com
Open sourcelore.kernel.org
Open sourcegithub.com
Open sourcegithub.com
Open sourcelore.kernel.org
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.