Junglewise Threat Intelligence

CVE-2025-40039: Linux Kernel ksmbd race condition in RPC handle list access

CVE-2025-40039 · Severity: high · CVSS 8.8 · Published 2025-10-28

Technologies: Linux Kernel. Vendors: Linux.

Executive brief

A vulnerability exists in the Linux kernel's ksmbd component, which provides SMB file-sharing services. A flaw in how the system manages internal communication handles could allow an attacker to cause system instability or potentially gain unauthorized access to data. This issue stems from a race condition where multiple processes might try to modify the same data simultaneously due to improper locking.

Technical details

A race condition exists in the ksmbd module of the Linux kernel within the management of 'sess->rpc_handle_list'. The vulnerability is caused by improper use of rw_semaphores; specifically, ksmbd_session_rpc_open() incorrectly acquired a read lock instead of a write lock before performing xa_store() and xa_erase() operations on the XArray. Additionally, ksmbd_session_rpc_method() performed xa_load() without any locking. These flaws allow for concurrent modifications and lookups that can result in data corruption or a use-after-free (UAF) if an entry is dereferenced after being removed. The fix involves upgrading to write locks for modifications and ensuring read locks are held during lookups.

Affected products

  • Linux Linux Kernel 5.15.145 to 6.17.3; 6.18 and later fixed

Timeline

  • 2025-09-30: patched: Initial patch committed to stable tree
  • 2025-10-28: disclosed: CVE published

References

Related threats