Executive brief
A race condition vulnerability was identified in the Linux kernel's SMB client, which is used to connect to network file shares. When a file is being renamed, there is a brief window where other processes can simultaneously attempt to open the same file, potentially leading to system instability or unauthorized data access. This issue affects Linux-based systems and certain industrial networking components like the Siemens SIMATIC CN 4100.
Technical details
A race condition exists in the Linux kernel SMB client (cifs.ko) within the rename(2) implementation. The vulnerability occurs because the rename process involves multiple steps—closing deferred handles, waiting for I/O, and marking handles as deleted—which creates a timing window where concurrent open requests can target the file being renamed. An attacker with local access could exploit this improper synchronization (CWE-362) to cause a denial of service or potentially manipulate file data. The fix involves unhashing the dentry in advance to prevent concurrent lookups/opens during the rename operation. Patches have been released for various stable kernel branches including 6.1.y, 6.6.y, and 6.12.y.
Affected products
- Linux Linux Kernel 5.13 to 6.1.150, 6.6.104, 6.12.45, 6.16.5
- Siemens SIMATIC CN 4100 before V5.0
Timeline
- 2025-08-08: patched: Original patch authored by Paulo Alcantara
- 2025-09-16: disclosed: CVE published to NVD
References
- https://git.kernel.org/stable/c/24b9ed739c8c5b464d983e12cf308982f3ae93c2
- https://git.kernel.org/stable/c/289f945acb20b9b54fe4d13895e44aa58965ddb2
- https://git.kernel.org/stable/c/c9991af5e09924f6f3b3e6996a5e09f9504b4358
- https://git.kernel.org/stable/c/c9e7de284da0be5b44dbe79d71573f9f7f9b144c
- https://git.kernel.org/stable/c/d84291fc7453df7881a970716f8256273aca5747
- https://lists.debian.org/debian-lts-announce/2025/10/msg00008.html
- https://cert-portal.siemens.com/productcert/html/ssa-032379.html