CVE-2025-39888: Linux Kernel

High severity, CVSS 7.8. EPSS: 0.1% chance of exploitation in the next 30 days.

In the Linux kernel, the following vulnerability has been resolved: fuse: Block access to folio overlimit syz reported a slab-out-of-bounds Write in fuse_dev_do_write. When the number of bytes to be retrieved is truncated to the upper limit by fc->max_pages and there is an offset, the oob is triggered. Add a loop termination condition to prevent overruns.

Affected products

  • Linux Linux Kernel: from 6.16, before 6.16.8 (fixed in 6.16.8); version 6.17 only

Published 2025-09-23. Last modified 2026-06-17.