Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

CVE-2025-40320— smb: client: fix potential cfid UAF in smb2_query_info_compound

CVSS 9.8 · Critical EPSS 0.41% · P34

Affected Version Matrix 11

VendorProductVersion RangeStatus
LinuxLinux433042a91f9373241307725b52de573933ffedbf< 939c4e33005e2a56ea8fcedddf0da92df864bd3baffected
4f1fffa2376922f3d1d506e49c0fd445b023a28e< 327f89c21601ebb7889f8c97754b76f08ce95a0caffected
4f1fffa2376922f3d1d506e49c0fd445b023a28e< b556c278d43f4707a9073ca74d55581b4f279806affected
4f1fffa2376922f3d1d506e49c0fd445b023a28e< 5c76f9961c170552c1d07c830b5e145475151600affected
6.6.32< 6.6.117affected
6.8affected
< 6.8unaffected
6.6.117≤ 6.6.*unaffected
… +3 more rows
Get alerts for future matching vulnerabilitiesLog in to subscribe

I. Basic Information for CVE-2025-40320

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
smb: client: fix potential cfid UAF in smb2_query_info_compound
Source: CVE Program / CVE List V5
Vulnerability Description
In the Linux kernel, the following vulnerability has been resolved: smb: client: fix potential cfid UAF in smb2_query_info_compound When smb2_query_info_compound() retries, a previously allocated cfid may have been freed in the first attempt. Because cfid wasn't reset on replay, later cleanup could act on a stale pointer, leading to a potential use-after-free. Reinitialize cfid to NULL under the replay label. Example trace (trimmed): refcount_t: underflow; use-after-free. WARNING: CPU: 1 PID: 11224 at ../lib/refcount.c:28 refcount_warn_saturate+0x9c/0x110 [...] RIP: 0010:refcount_warn_saturate+0x9c/0x110 [...] Call Trace: <TASK> smb2_query_info_compound+0x29c/0x5c0 [cifs f90b72658819bd21c94769b6a652029a07a7172f] ? step_into+0x10d/0x690 ? __legitimize_path+0x28/0x60 smb2_queryfs+0x6a/0xf0 [cifs f90b72658819bd21c94769b6a652029a07a7172f] smb311_queryfs+0x12d/0x140 [cifs f90b72658819bd21c94769b6a652029a07a7172f] ? kmem_cache_alloc+0x18a/0x340 ? getname_flags+0x46/0x1e0 cifs_statfs+0x9f/0x2b0 [cifs f90b72658819bd21c94769b6a652029a07a7172f] statfs_by_dentry+0x67/0x90 vfs_statfs+0x16/0xd0 user_statfs+0x54/0xa0 __do_sys_statfs+0x20/0x50 do_syscall_64+0x58/0x80
Source: CVE Program / CVE List V5
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Source: CVE Program / CVE List V5
Vulnerability Type
N/A
Source: CVE Program / CVE List V5
Vulnerability Title
Linux kernel 安全漏洞
Source: CNNVD (China National Vulnerability Database)
Vulnerability Description
Linux kernel是美国Linux基金会的开源操作系统Linux所使用的内核。 Linux kernel存在安全漏洞,该漏洞源于释放后重用,可能导致内存损坏。
Source: CNNVD (China National Vulnerability Database)
CVSS Information
N/A
Source: CNNVD (China National Vulnerability Database)
Vulnerability Type
N/A
Source: CNNVD (China National Vulnerability Database)

Affected Products

VendorProductAffected VersionsCPESubscribe
LinuxLinux 433042a91f9373241307725b52de573933ffedbf ~ 939c4e33005e2a56ea8fcedddf0da92df864bd3b -
LinuxLinux 6.8 -

II. Public POCs for CVE-2025-40320

#POC DescriptionSource LinkShenlong Link
AI-Generated POCPremium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2025-40320

登录查看更多情报信息。

Same Patch Batch · Linux · 2025-12-08 · 82 CVEs total

CVE-2023-537519.8 CRITICALcifs: fix potential use-after-free bugs in TCP_Server_Info::hostname
CVE-2023-537699.3 CRITICALvirt/coco/sev-guest: Double-buffer messages
CVE-2023-537648.8 HIGHwifi: ath12k: Handle lock during peer_id find
CVE-2025-403188.8 HIGHBluetooth: hci_sync: fix race in hci_cmd_sync_dequeue_once
CVE-2023-537628.8 HIGHBluetooth: hci_sync: Fix UAF in hci_disconnect_all_sync
CVE-2025-402928.4 HIGHvirtio-net: fix received length check in big packets
CVE-2025-403098.0 HIGHBluetooth: SCO: Fix UAF on sco_conn_free
CVE-2025-403027.8 HIGHmedia: videobuf2: forbid remove_bufs when legacy fileio is active
CVE-2023-537637.8 HIGHRevert "f2fs: fix to do sanity check on extent cache correctly"
CVE-2023-537687.8 HIGHregmap-irq: Fix out-of-bounds access when allocating config buffers
CVE-2025-402977.8 HIGHnet: bridge: fix use-after-free due to MST port state bypass
CVE-2022-506307.8 HIGHmm: hugetlb: fix UAF in hugetlb_handle_userfault
CVE-2022-506237.8 HIGHfpga: prevent integer overflow in dfl_feature_ioctl_set_irq()
CVE-2023-537597.8 HIGHHID: hidraw: fix data race on device refcount
CVE-2025-403177.8 HIGHregmap: slimbus: fix bus_context pointer in regmap init calls
CVE-2025-403197.8 HIGHbpf: Sync pending IRQ work before freeing ring buffer
CVE-2023-537477.8 HIGHvc_screen: reload load of struct vc_data pointer in vcs_write() to avoid UAF
CVE-2025-403237.8 HIGHfbcon: Set fb_display[i]->mode to NULL when the mode is released
CVE-2023-537537.8 HIGHdrm/amd/display: fix mapping to non-allocated address
CVE-2023-537527.8 HIGHnet: deal with integer overflows in kmalloc_reserve()

Showing top 20 of 82 CVEs. View all on vendor page &rarr; →

IV. Related Vulnerabilities

V. Comments for CVE-2025-40320

No comments yet


Leave a comment