Junglewise Threat Intelligence

CVE-2025-40168: Linux Kernel use-after-free in smc_clc_prfx_match

CVE-2025-40168 · Severity: high · CVSS 8.1 · Published 2025-11-12

Technologies: Linux Kernel. Vendors: Linux.

Executive brief

A vulnerability was identified in the Linux kernel's Shared Memory Communications (SMC) protocol, which is used for high-performance data transfers. A flaw in how the system handles network destination information could lead to a system crash or unauthorized memory access. This could potentially impact the stability and security of servers utilizing SMC for network traffic.

Technical details

A use-after-free (UAF) vulnerability exists in the Linux kernel's SMC implementation within the 'smc_clc_prfx_match' function in 'net/smc/smc_clc.c'. The issue arises because 'smc_clc_prfx_match' is called from 'smc_listen_work' without proper RCU or RTNL locking, leading to a race condition when accessing 'sk_dst_get(sk)->dev'. An attacker could potentially exploit this race condition to trigger a UAF state. The fix involves migrating to '__sk_dst_get()' and 'dst_dev_rcu()' to ensure safe RCU-protected access to the network device. Patches have been released in various stable kernel branches including 6.18 and backported to earlier versions.

Affected products

  • Linux Linux Kernel 4.11 to 6.17.3

Timeline

  • 2025-09-16: patched: Initial fix commit authored
  • 2025-11-12: disclosed: CVE published

References

Related threats