Junglewise Threat Intelligence

CVE-2025-40139: Linux Kernel use-after-free in smc_clc_prfx_set

CVE-2025-40139 · Severity: high · CVSS 7.8 · Published 2025-11-12

Technologies: Linux Kernel. Vendors: Linux.

Executive brief

A vulnerability was identified in the Linux kernel's Shared Memory Communications (SMC) protocol, which is used for high-performance data exchange. A flaw in how the system handles network device information during a connection could lead to a system crash or unauthorized memory access. This could allow a local attacker to compromise the stability of the system or potentially access sensitive information.

Technical details

A use-after-free (UAF) vulnerability exists in the Linux kernel's SMC implementation within the 'smc_clc_prfx_set()' function. The issue arises because the function accesses 'sk_dst_get(sk)->dev' without proper RCU (Read-Copy-Update) or RTNL (Routing Netlink) locking during a connection handshake. An attacker with local access could exploit this race condition to trigger a UAF, potentially leading to a kernel crash or arbitrary code execution. The fix involves using '__sk_dst_get()' and 'dst_dev_rcu()' within an 'rcu_read_lock()' block to ensure safe access to the network device structure. Patches have been released in stable kernel versions including 6.18 and backported to earlier stable branches.

Affected products

  • Linux Linux Kernel 4.11 to 6.17.3

Timeline

  • 2025-09-16: patched: Initial fix commit authored
  • 2025-11-12: disclosed: CVE published

References

Related threats