CVE-2025-40320 — Expired Pointer Dereference in Linux
Severity
3.2LOWOSV
No vectorEPSS
0.0%
top 90.17%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedDec 8
Latest updateApr 9
Description
In the Linux kernel, the following vulnerability has been resolved:
smb: client: fix potential cfid UAF in smb2_query_info_compound
When smb2_query_info_compound() retries, a previously allocated cfid may
have been freed in the first attempt.
Because cfid wasn't reset on replay, later cleanup could act on a stale
pointer, leading to a potential use-after-free.
Reinitialize cfid to NULL under the replay label.
Example trace (trimmed):
refcount_t: underflow; use-after-free.
WARNING: CPU: 1 PI…
Affected Packages14 packages
▶CVEListV5linux/linux433042a91f9373241307725b52de573933ffedbf — 939c4e33005e2a56ea8fcedddf0da92df864bd3b+4