In the Linux kernel, the following vulnerability has been resolved: NFS: Fix a race when updating an existing write After nfs_lock_and_join_requests() tests for whether the request is still attached to the mapping, nothing prevents a call to nfs_inode_remove_request() from succeeding until we actually lock the page group. The reason is that whoever called nfs_inode_remove_request() doesn't necessarily have a lock on the page group head. So in order to avoid races, let's take the page group lock earlier in nfs_lock_and_join_requests(), and hold it across the removal of the request in nfs_inode_remove_request().
Upstream advisory: https://lore.kernel.org/linux-cve-announce/2025090548-CVE-2025-39697-5284@gregkh/T
This issue has been addressed in the following products: Red Hat Enterprise Linux 10 Via RHSA-2025:19106 https://access.redhat.com/errata/RHSA-2025:19106
This issue has been addressed in the following products: Red Hat Enterprise Linux 9.2 Update Services for SAP Solutions Via RHSA-2025:21051 https://access.redhat.com/errata/RHSA-2025:21051
This issue has been addressed in the following products: Red Hat Enterprise Linux 9.0 Update Services for SAP Solutions Via RHSA-2025:21091 https://access.redhat.com/errata/RHSA-2025:21091
This issue has been addressed in the following products: Red Hat Enterprise Linux 10 Via RHSA-2025:21118 https://access.redhat.com/errata/RHSA-2025:21118
This issue has been addressed in the following products: Red Hat Enterprise Linux 9.2 Update Services for SAP Solutions Via RHSA-2025:21128 https://access.redhat.com/errata/RHSA-2025:21128
This issue has been addressed in the following products: Red Hat Enterprise Linux 9.0 Update Services for SAP Solutions Via RHSA-2025:21136 https://access.redhat.com/errata/RHSA-2025:21136
This issue has been addressed in the following products: Red Hat Enterprise Linux 9 Via RHSA-2025:21469 https://access.redhat.com/errata/RHSA-2025:21469
This issue has been addressed in the following products: Red Hat Enterprise Linux 9.4 Extended Update Support Via RHSA-2025:21760 https://access.redhat.com/errata/RHSA-2025:21760
This issue has been addressed in the following products: Red Hat Enterprise Linux 8 Via RHSA-2025:21917 https://access.redhat.com/errata/RHSA-2025:21917
This issue has been addressed in the following products: Red Hat Enterprise Linux 8 Via RHSA-2025:21920 https://access.redhat.com/errata/RHSA-2025:21920
This issue has been addressed in the following products: Red Hat Enterprise Linux 8.6 Advanced Mission Critical Update Support Red Hat Enterprise Linux 8.6 Update Services for SAP Solutions Red Hat Enterprise Linux 8.6 Telecommunications Update Service Via RHSA-2025:22006 https://access.redhat.com/errata/RHSA-2025:22006