Junglewise Threat Intelligence

CVE-2025-38728: Linux Kernel SMB3 out-of-bounds read in parse_server_interfaces

CVE-2025-38728 · Severity: critical · CVSS 9.1 · Published 2025-09-04

Technologies: Siemens SIMATIC CN 4100, Linux Kernel. Vendors: Siemens, Linux.

Executive brief

A vulnerability exists in the Linux kernel's SMB3 client, which is used to connect to network file shares. An attacker could potentially exploit this flaw during the process of mounting a network drive to cause a system crash or access sensitive information from the system's memory. This could lead to a loss of service or unauthorized data exposure on affected Linux systems and certain industrial hardware.

Technical details

An out-of-bounds (OOB) read vulnerability exists in the Linux kernel SMB3 client (cifs.ko) within the parse_server_interfaces() function in fs/smb/client/smb2ops.c. The root cause is a missing bounds check when processing the 'Next' pointer in the network interface information ioctl response; if the pointer exceeds the remaining buffer size, the kernel performs an out-of-bounds access. This can be triggered during a mount operation to a ksmbd server. An attacker can leverage this to cause a kernel panic (DoS) or potentially leak sensitive kernel memory. Patches have been released for various stable kernel branches including 6.1, 6.6, and 6.10+.

Affected products

  • Linux Linux Kernel 4.18 to 6.16-rc2
  • Siemens SIMATIC CN 4100 before V5.0

Timeline

  • 2025-08-11: patched: Initial fix committed to Linux kernel tree
  • 2025-09-04: disclosed: CVE published

References

Related threats