Junglewise Threat Intelligence

CVE-2025-39692: Linux Kernel ksmbd NULL pointer dereference in RDMA transport

CVE-2025-39692 · Severity: medium · CVSS 5.5 · Published 2025-09-05

Technologies: Linux Kernel. Vendors: Linux.

Executive brief

A vulnerability was identified in the Linux kernel's SMB server component (ksmbd) when using RDMA networking. During the shutdown process of the file server, a race condition could occur where the system attempts to use a network resource that has already been deleted. This can lead to a system crash (denial of service), potentially disrupting file sharing operations for users and applications.

Technical details

A NULL pointer dereference vulnerability exists in the Linux kernel SMB server (ksmbd) within the RDMA transport implementation. The issue is caused by an incorrect teardown sequence in 'ksmbd_conn_transport_destroy()', where 'destroy_workqueue(smb_direct_wq)' was being called via 'ksmbd_rdma_destroy()' before 'stop_sessions()'. This allowed existing active connections to attempt to access the 'smb_direct_wq' workqueue after it had been freed and set to NULL. The fix involves splitting the RDMA teardown into two phases: stopping the listener first, then stopping sessions, and finally destroying the workqueue. This vulnerability is reachable by a local attacker or through specific service management actions, resulting in a kernel oops and denial of service.

Affected products

  • Linux Linux Kernel 5.15 to 6.1.149, 6.2 to 6.6.103, 6.7 to 6.12.44, 6.13 to 6.16.4

Timeline

  • 2025-08-12: other: Patch authored
  • 2025-09-05: disclosed: CVE published
  • 2025-08-28: patched: Patch committed to stable trees

References

Related threats