Junglewise Threat Intelligence

CVE-2025-39819: Linux Kernel resource leak in fs/smb smb2_compound_op

CVE-2025-39819 · Severity: medium · CVSS 5.5 · Published 2025-09-16

Technologies: Linux Kernel. Vendors: Linux.

Executive brief

A vulnerability was identified in the Linux kernel's SMB (Server Message Block) file system client, which is used to connect to network shared folders. A technical error in how the system tracks file references can lead to resource leaks when the system runs out of memory. This could potentially be used by a local attacker to cause a system slowdown or crash by exhausting available resources.

Technical details

A vulnerability in `fs/smb/client/smb2inode.c` within the Linux kernel involves an inconsistent reference count update in the `smb2_compound_op` function. When a memory allocation failure (-ENOMEM) occurs for the `vars` structure, the function returns immediately without dropping the reference to the `cfile` object. This leads to a reference count leak, as callers of this function do not handle the cleanup when this specific error is returned. An attacker with local access could potentially exploit this to cause resource exhaustion. The fix introduces a unified exit path (goto label) to ensure `cifsFileInfo_put` is called regardless of the allocation outcome.

Affected products

  • Linux Linux Kernel 5.8 to 6.1.150, 6.2 to 6.6.104, 6.7 to 6.12.45, 6.13 to 6.16.5

Timeline

  • 2025-08-28: patched: Initial patch authored
  • 2025-09-16: disclosed: CVE published

References

Related threats