Junglewise Threat Intelligence

CVE-2025-40064: Linux Kernel use-after-free in SMC __pnet_find_base_ndev

CVE-2025-40064 · Severity: high · CVSS 7.8 · Published 2025-10-28

Technologies: Linux Kernel. Vendors: Linux.

Executive brief

A vulnerability was found in the Linux kernel's Shared Memory Communications (SMC) protocol, which is used for high-performance data exchange. A flaw in how the system handles network device references could allow a local attacker to cause a system crash or potentially execute unauthorized code. This issue primarily impacts system stability and the reliability of high-speed networking operations.

Technical details

A use-after-free (UAF) vulnerability exists in the Linux kernel's SMC implementation within the __pnet_find_base_ndev() function. The root cause is a race condition where a net_device pointer is fetched via sk_dst_get() but its reference count is not properly incremented before the routine attempts to acquire the RTNL lock. Consequently, the device can be freed or replaced by a blackhole_netdev while the code is still attempting to use it. This affects both smc_pnet_find_ism_resource() and smc_pnet_find_roce_resource(). A local attacker can trigger this during a connect() system call to cause a kernel panic or potentially achieve privilege escalation. The fix involves using __sk_dst_get() and dst_dev_rcu() to properly manage device reference counts.

Affected products

  • Linux Linux Kernel 0afff91c6f5ecef27715ea71e34dc2baacba1060

Timeline

  • 2025-09-16: other: Patch authored
  • 2025-10-28: disclosed: CVE published

References

Related threats