Executive brief
A vulnerability in the Linux kernel's CIFS (Common Internet File System) client could allow a local user to crash the system. The issue occurs during the conversion of file names or data to the UTF-16 format used by Windows-compatible network shares. An exploit would result in a kernel panic (system crash), leading to a denial of service and potential loss of unsaved data.
Technical details
A NULL pointer dereference exists in the Linux kernel's CIFS/SMB client implementation. The vulnerability occurs when a NULL pointer is passed to '__cifs_sfu_make_node' without validation, which subsequently flows through 'cifs_strndup_to_utf16' to 'cifs_local_to_utf16_bytes' where it is dereferenced. A local attacker with low privileges can trigger this flaw to cause a kernel oops and system crash (Denial of Service). The issue has been resolved by adding a NULL check in 'cifs_strndup_to_utf16' to return early if the source string is missing.
Affected products
- Linux Linux Kernel 6.12 to 6.12.46, 6.13 to 6.16.6, 6.17-rc1 to 6.17-rc4
Timeline
- 2025-09-04: patched: Initial patch submitted to the Linux kernel tree.
- 2025-09-19: disclosed: CVE-2025-39838 published.
- 2025-10-13: advisory: Debian LTS advisory DLA-4328-1 released.
References
- https://git.kernel.org/stable/c/1f797f062b5cf13a1c2bcc23285361baaa7c9260
- https://git.kernel.org/stable/c/3c26a8d30ed6b53a52a023ec537dc50a6d34a67a
- https://git.kernel.org/stable/c/70bccd9855dae56942f2b18a08ba137bb54093a0
- https://lists.debian.org/debian-lts-announce/2025/10/msg00008.html
- https://cert-portal.siemens.com/productcert/html/ssa-032379.html