Junglewise Threat Intelligence

CVE-2025-39825: Linux Kernel SMB client race condition in rename operation

CVE-2025-39825 · Severity: high · CVSS 7.8 · Published 2025-09-16

Technologies: Linux Kernel, Siemens SIMATIC CN 4100. Vendors: Linux, Siemens.

Executive brief

A race condition vulnerability was identified in the Linux kernel's SMB client, which is used to connect to network file shares. When a file is being renamed, there is a brief window where other processes can simultaneously attempt to open the same file, potentially leading to system instability or unauthorized data access. This issue affects Linux-based systems and certain industrial networking components like the Siemens SIMATIC CN 4100.

Technical details

A race condition exists in the Linux kernel SMB client (cifs.ko) within the rename(2) implementation. The vulnerability occurs because the rename process involves multiple steps—closing deferred handles, waiting for I/O, and marking handles as deleted—which creates a timing window where concurrent open requests can target the file being renamed. An attacker with local access could exploit this improper synchronization (CWE-362) to cause a denial of service or potentially manipulate file data. The fix involves unhashing the dentry in advance to prevent concurrent lookups/opens during the rename operation. Patches have been released for various stable kernel branches including 6.1.y, 6.6.y, and 6.12.y.

Affected products

  • Linux Linux Kernel 5.13 to 6.1.150, 6.6.104, 6.12.45, 6.16.5
  • Siemens SIMATIC CN 4100 before V5.0

Timeline

  • 2025-08-08: patched: Original patch authored by Paulo Alcantara
  • 2025-09-16: disclosed: CVE published to NVD

References

Related threats