Executive brief
A vulnerability was identified in the Linux kernel's networking stack involving how it handles TCP Fast Open (TFO) connections. If a network service is closed while a specific type of connection request is being processed, it can lead to a system crash or memory corruption. This could potentially allow an attacker to disrupt service availability or, in complex scenarios, compromise system integrity.
Technical details
A race condition exists in `tcp_conn_request()` where a double-free of `reqsk` and a reference count underflow for the listener socket can occur. If a listener is closed while a TFO socket is being processed, `inet_csk_reqsk_queue_add()` fails to set `reqsk->sk` and triggers `inet_child_forget()`, which calls `tcp_disconnect()`. Because `tcp_disconnect()` now internally calls `reqsk_fastopen_remove()`, the subsequent manual call to `reqsk_fastopen_remove()` in `tcp_conn_request()` results in redundant refcount decrements and a double-free during the `drop_and_free` error path. The fix involves removing the redundant `reqsk_fastopen_remove()` call in `tcp_conn_request()`.
Affected products
- Linux Linux Kernel 7ec092a91ff3, a4378dedd6e0, 33a4fdf0b4a2, 17d699727577, dfd06131107e, fa4749c06564, 45c8a6cc2bcd
Timeline
- 2025-10-01: patched: Initial patch authored
- 2025-11-12: advisory: CVE-2025-40186 published
References
- https://git.kernel.org/stable/c/2e7cbbbe3d61c63606994b7ff73c72537afe2e1c
- https://git.kernel.org/stable/c/422c1c173c39bbbae1e0eaaf8aefe40b2596233b
- https://git.kernel.org/stable/c/643a94b0cf767325e953591c212be2eb826b9d7f
- https://git.kernel.org/stable/c/64dc47a13aa3d9daf7cec29b44dca8e22a6aea15
- https://git.kernel.org/stable/c/c11ace909e873118295e9eb22dc8c58b0b50eb32
- https://git.kernel.org/stable/c/e359b742eac1eac75cff4e38ee2e8cea492acd9b
- https://git.kernel.org/stable/c/eb85ad5f23268d64b037bfb545cbcba3752f90c7