Junglewise Threat Intelligence

CVE-2025-40186: Linux Kernel double-free in TCP Fast Open connection handling

CVE-2025-40186 · Severity: high · CVSS 8.1 · Published 2025-11-12

Technologies: Linux Kernel. Vendors: Linux.

Executive brief

A vulnerability was identified in the Linux kernel's networking stack involving how it handles TCP Fast Open (TFO) connections. If a network service is closed while a specific type of connection request is being processed, it can lead to a system crash or memory corruption. This could potentially allow an attacker to disrupt service availability or, in complex scenarios, compromise system integrity.

Technical details

A race condition exists in `tcp_conn_request()` where a double-free of `reqsk` and a reference count underflow for the listener socket can occur. If a listener is closed while a TFO socket is being processed, `inet_csk_reqsk_queue_add()` fails to set `reqsk->sk` and triggers `inet_child_forget()`, which calls `tcp_disconnect()`. Because `tcp_disconnect()` now internally calls `reqsk_fastopen_remove()`, the subsequent manual call to `reqsk_fastopen_remove()` in `tcp_conn_request()` results in redundant refcount decrements and a double-free during the `drop_and_free` error path. The fix involves removing the redundant `reqsk_fastopen_remove()` call in `tcp_conn_request()`.

Affected products

  • Linux Linux Kernel 7ec092a91ff3, a4378dedd6e0, 33a4fdf0b4a2, 17d699727577, dfd06131107e, fa4749c06564, 45c8a6cc2bcd

Timeline

  • 2025-10-01: patched: Initial patch authored
  • 2025-11-12: advisory: CVE-2025-40186 published

References

Related threats