CVE-2025-40090Uncontrolled Recursion in Linux

Severity
5.5MEDIUMNVD
EPSS
0.0%
top 98.89%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedOct 30

Description

In the Linux kernel, the following vulnerability has been resolved: ksmbd: fix recursive locking in RPC handle list access Since commit 305853cce3794 ("ksmbd: Fix race condition in RPC handle list access"), ksmbd_session_rpc_method() attempts to lock sess->rpc_lock. This causes hung connections / tasks when a client attempts to open a named pipe. Using Samba's rpcclient tool: $ rpcclient //192.168.1.254 -U user%password $ rpcclient $> srvinfo Kernel side: "echo 0 > /proc/sys/kernel/hung_ta

CVSS vector

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:HExploitability: 1.8 | Impact: 3.6

Affected Packages4 packages

NVDlinux/linux_kernel6.12.536.12.55+2
CVEListV5linux/linux69674b029002b1d90b655f014bdf64f404efa54d5493571f4351f74e11db9943e98a07c56467cf7e+6
debiandebian/linux

Patches

🔴Vulnerability Details

2
OSV
CVE-2025-40090: In the Linux kernel, the following vulnerability has been resolved: ksmbd: fix recursive locking in RPC handle list access Since commit 305853cce37942025-10-30
GHSA
GHSA-m33j-r627-qphr: In the Linux kernel, the following vulnerability has been resolved: ksmbd: fix recursive locking in RPC handle list access Since commit 305853cce3792025-10-30

📋Vendor Advisories

3
Red Hat
kernel: ksmbd: fix recursive locking in RPC handle list access2025-10-30
Microsoft
ksmbd: fix recursive locking in RPC handle list access2025-10-14
Debian
CVE-2025-40090: linux - In the Linux kernel, the following vulnerability has been resolved: ksmbd: fix ...2025