Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

CVE-2025-40237— fs/notify: call exportfs_encode_fid with s_umount

Quick assessment

Affected
Linux Linux
Exploitation
No confirmed in-the-wild exploitation; assess based on exposure
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

Linux kernel是美国Linux基金会的开源操作系统Linux所使用的内核。 Linux kernel存在安全漏洞,该漏洞源于exportfs_encode_fid未在s_umount保护下调用,可能导致空指针解引用。

AI Predicted 5.5 Difficulty: Hard EPSS 0.20% · P9

Affected Version Matrix 15

VendorProduct Version RangeStatus
Linux Linux a1a541fbfa7e97c1100144db34b57553d7164ce5< 950b604384fd75d62e860bec7135b2b62eb4d508 affected
f0c0ac84de17c37e6e84da65fb920f91dada55ad< bc1c6b803e14ea2b8f7e33b7164013f666ceb656 affected
3c7c90274ae339e1ad443c9be1c67a20b80b9c76< 3f307a9f7a7a2822e38ac451b73e2244e7279496 affected
c45beebfde34aa71afbc48b2c54cdda623515037< d1894bc542becb0fda61e7e513b09523cab44030 affected
c45beebfde34aa71afbc48b2c54cdda623515037< a7c4bb43bfdc2b9f06ee9d036028ed13a83df42a affected
6.6.72< 6.6.73 affected
6.6.74< 6.6.115 affected
6.12.10< 6.12.56 affected
… +7 more rows
Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2025-40237

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
fs/notify: call exportfs_encode_fid with s_umount
Source: CVE Program / CVE List V5
Vulnerability Description
In the Linux kernel, the following vulnerability has been resolved: fs/notify: call exportfs_encode_fid with s_umount Calling intotify_show_fdinfo() on fd watching an overlayfs inode, while the overlayfs is being unmounted, can lead to dereferencing NULL ptr. This issue was found by syzkaller. Race Condition Diagram: Thread 1 Thread 2 -------- -------- generic_shutdown_super() shrink_dcache_for_umount sb->s_root = NULL | | vfs_read() | inotify_fdinfo() | * inode get from mark * | show_mark_fhandle(m, inode) | exportfs_encode_fid(inode, ..) | ovl_encode_fh(inode, ..) | ovl_check_encode_origin(inode) | * deref i_sb->s_root * | | v fsnotify_sb_delete(sb) Which then leads to: [ 32.133461] Oops: general protection fault, probably for non-canonical address 0xdffffc0000000006: 0000 [#1] SMP DEBUG_PAGEALLOC KASAN NOPTI [ 32.134438] KASAN: null-ptr-deref in range [0x0000000000000030-0x0000000000000037] [ 32.135032] CPU: 1 UID: 0 PID: 4468 Comm: systemd-coredum Not tainted 6.17.0-rc6 #22 PREEMPT(none) <snip registers, unreliable trace> [ 32.143353] Call Trace: [ 32.143732] ovl_encode_fh+0xd5/0x170 [ 32.144031] exportfs_encode_inode_fh+0x12f/0x300 [ 32.144425] show_mark_fhandle+0xbe/0x1f0 [ 32.145805] inotify_fdinfo+0x226/0x2d0 [ 32.146442] inotify_show_fdinfo+0x1c5/0x350 [ 32.147168] seq_show+0x530/0x6f0 [ 32.147449] seq_read_iter+0x503/0x12a0 [ 32.148419] seq_read+0x31f/0x410 [ 32.150714] vfs_read+0x1f0/0x9e0 [ 32.152297] ksys_read+0x125/0x240 IOW ovl_check_encode_origin derefs inode->i_sb->s_root, after it was set to NULL in the unmount path. Fix it by protecting calling exportfs_encode_fid() from show_mark_fhandle() with s_umount lock. This form of fix was suggested by Amir in [1]. [1]: https://lore.kernel.org/all/CAOQ4uxhbDwhb+2Brs1UdkoF0a3NSdBAOQPNfEHjahrgoKJpLEw@mail.gmail.com/
Source: CVE Program / CVE List V5
CVSS Information
N/A
Source: CVE Program / CVE List V5
Vulnerability Type
N/A
Source: CVE Program / CVE List V5
Vulnerability Title
Linux kernel 安全漏洞
Source: CNNVD (China National Vulnerability Database)
Vulnerability Description
Linux kernel是美国Linux基金会的开源操作系统Linux所使用的内核。 Linux kernel存在安全漏洞,该漏洞源于exportfs_encode_fid未在s_umount保护下调用,可能导致空指针解引用。
Source: CNNVD (China National Vulnerability Database)
CVSS Information
N/A
Source: CNNVD (China National Vulnerability Database)
Vulnerability Type
N/A
Source: CNNVD (China National Vulnerability Database)

Affected Products

Vendor Product Affected Versions CPE Subscribe
Linux Linux a1a541fbfa7e97c1100144db34b57553d7164ce5 ~ 950b604384fd75d62e860bec7135b2b62eb4d508 -
Linux Linux 6.13 -

II. Public POCs for CVE-2025-40237

# POC Description Source Link Shenlong Link
AI-Generated POC Premium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2025-40237

请登录查看更多情报信息。

Same Patch Batch · Linux · 2025-12-04 · 53 CVEs total

CVE-2025-40261 9.8 CRITICAL nvme: nvme-fc: Ensure ->ioerr_work is cancelled in nvme_fc_delete_ctrl()
CVE-2025-40252 9.8 CRITICAL net: qlogic/qede: fix potential out-of-bounds read in qede_tpa_cont() and qede_tpa_end()
CVE-2025-40258 9.8 CRITICAL mptcp: fix race condition in mptcp_schedule_work()
CVE-2025-40257 9.8 CRITICAL mptcp: fix a race in mptcp_pm_del_add_timer()
CVE-2025-40253 8.8 HIGH s390/ctcm: Fix double-kfree
CVE-2025-40266 8.2 HIGH KVM: arm64: Check the untrusted offset in FF-A memory share
CVE-2025-40244 7.8 HIGH hfsplus: fix KMSAN uninit-value issue in __hfsplus_ext_cache_extent()
CVE-2025-40251 7.8 HIGH devlink: rate: Unset parent pointer in devl_rate_nodes_destroy
CVE-2025-40262 7.8 HIGH Input: imx_sc_key - fix memory corruption on unload
CVE-2025-40250 7.8 HIGH net/mlx5: Clean up only new IRQ glue on request_irq() failure
CVE-2025-40248 7.8 HIGH vsock: Ignore signal/timeout on connect() if already established
CVE-2025-40249 7.8 HIGH gpio: cdev: make sure the cdev fd is still active before emitting events
CVE-2025-40245 7.8 HIGH nios2: ensure that memblock.current_limit is set when setting pfn limits
CVE-2025-40214 7.8 HIGH af_unix: Initialise scc_index in unix_add_edge().
CVE-2025-40243 7.8 HIGH hfs: fix KMSAN uninit-value issue in hfs_find_set_zero_bits()
CVE-2025-40241 7.8 HIGH erofs: fix crafted invalid cases for encoded extents
CVE-2025-40233 7.8 HIGH ocfs2: clear extent cache after moving/defragmenting extents
CVE-2025-40216 7.8 HIGH io_uring/rsrc: don't rely on user vaddr alignment
CVE-2025-40215 7.8 HIGH xfrm: delete x->tunnel as we delete x
CVE-2025-40240 7.5 HIGH sctp: avoid NULL dereference when chunk data buffer is missing

Showing top 20 of 53 CVEs. View all on vendor page &rarr; →

IV. Related Vulnerabilities

V. Comments for CVE-2025-40237

No comments yet


Leave a comment