Junglewise Threat Intelligence

CVE-2025-38734: Linux Kernel use-after-free in net/smc listen work

CVE-2025-38734 · Severity: critical · CVSS 9.8 · Published 2025-09-05

Technologies: Linux Kernel. Vendors: Linux.

Executive brief

A vulnerability exists in the Linux kernel's Shared Memory Communications (SMC) networking protocol. If a user-space application closes a network connection immediately after accepting it, the kernel may attempt to access memory that has already been freed. This can lead to a system crash (denial of service) or potentially allow for unauthorized code execution, impacting the stability and security of servers using SMC for high-performance networking.

Technical details

A use-after-free (UAF) vulnerability exists in the Linux kernel's SMC protocol implementation within `net/smc/af_smc.c`. The issue is rooted in the `smc_listen_work` function, where `smc_listen_out_connected()` is called before updating statistics. Because `smc_listen_out()` releases the `smcsk` socket, a race condition occurs if a userspace application calls `close()` immediately after `accept()`, resulting in `newclcsock->sk` becoming NULL. When the kernel subsequently attempts to access this pointer for statistics via `SMC_STAT_SERV_SUCC_INC`, it triggers a NULL pointer dereference or UAF. The fix involves reordering the operations to ensure statistics are updated before the socket is released. Patches have been released for multiple stable kernel branches.

Affected products

  • Linux Linux Kernel 3b2dec2603d5 to 070b4af44c4b6e4c35fb1ca7001a6a88fd2d318f, 2e765ba0ee0eae35688b443e97108308a716773e, 85545f1525f9fa9bf44fec77ba011024f15da342, d9cef55ed49117bd63695446fb84b4b91815c0b4

Timeline

  • 2025-08-18: patched: Initial patch submitted by D. Wythe
  • 2025-09-05: disclosed: CVE published to NVD

References

Related threats