Executive brief
A vulnerability was identified in the Linux kernel's SMB server component (ksmbd) when using RDMA networking. During the shutdown process of the file server, a race condition could occur where the system attempts to use a network resource that has already been deleted. This can lead to a system crash (denial of service), potentially disrupting file sharing operations for users and applications.
Technical details
A NULL pointer dereference vulnerability exists in the Linux kernel SMB server (ksmbd) within the RDMA transport implementation. The issue is caused by an incorrect teardown sequence in 'ksmbd_conn_transport_destroy()', where 'destroy_workqueue(smb_direct_wq)' was being called via 'ksmbd_rdma_destroy()' before 'stop_sessions()'. This allowed existing active connections to attempt to access the 'smb_direct_wq' workqueue after it had been freed and set to NULL. The fix involves splitting the RDMA teardown into two phases: stopping the listener first, then stopping sessions, and finally destroying the workqueue. This vulnerability is reachable by a local attacker or through specific service management actions, resulting in a kernel oops and denial of service.
Affected products
- Linux Linux Kernel 5.15 to 6.1.149, 6.2 to 6.6.103, 6.7 to 6.12.44, 6.13 to 6.16.4
Timeline
- 2025-08-12: other: Patch authored
- 2025-09-05: disclosed: CVE published
- 2025-08-28: patched: Patch committed to stable trees
References
- https://git.kernel.org/stable/c/003e6a3150299f681f34cb189aa068018cef6a45
- https://git.kernel.org/stable/c/212eb86f75b4d7b82f3d94aed95ba61103bccb93
- https://git.kernel.org/stable/c/524e90e58a267dad11e23351d9e4b1f941490976
- https://git.kernel.org/stable/c/bac7b996d42e458a94578f4227795a0d4deef6fa
- https://git.kernel.org/stable/c/e41e33400516702427603f8fbbec43c91ede09c0
- https://lists.debian.org/debian-lts-announce/2025/10/msg00008.html
- https://cert-portal.siemens.com/productcert/html/ssa-032379.html