cbcvebase.
CVE-2025-40320
published 2025-12-08

CVE-2025-40320: In the Linux kernel, the following vulnerability has been resolved: smb: client: fix potential cfid UAF in smb2_query_info_compound When…

PriorityP347critical9.8CVSS 3.1
AVNACLPRNUINSUCHIHAH
EPSS
0.37%
29.8th percentile
In the Linux kernel, the following vulnerability has been resolved: smb: client: fix potential cfid UAF in smb2_query_info_compound When smb2_query_info_compound() retries, a previously allocated cfid may have been freed in the first attempt. Because cfid wasn't reset on replay, later cleanup could act on a stale pointer, leading to a potential use-after-free. Reinitialize cfid to NULL under the replay label. Example trace (trimmed): refcount_t: underflow; use-after-free. WARNING: CPU: 1 PID: 11224 at ../lib/refcount.c:28 refcount_warn_saturate+0x9c/0x110 [...] RIP: 0010:refcount_warn_saturate+0x9c/0x110 [...] Call Trace: smb2_query_info_compound+0x29c/0x5c0 [cifs f90b72658819bd21c94769b6a652029a07a7172f] ? step_into+0x10d/0x690 ? __legitimize_path+0x28/0x60 smb2_queryfs+0x6a/0xf0 [cifs f90b72658819bd21c94769b6a652029a07a7172f] smb311_queryfs+0x12d/0x140 [cifs f90b72658819bd21c94769b6a652029a07a7172f] ? kmem_cache_alloc+0x18a/0x340 ? getname_flags+0x46/0x1e0 cifs_statfs+0x9f/0x2b0 [cifs f90b72658819bd21c94769b6a652029a07a7172f] statfs_by_dentry+0x67/0x90 vfs_statfs+0x16/0xd0 user_statfs+0x54/0xa0 __do_sys_statfs+0x20/0x50 do_syscall_64+0x58/0x80

Affected

26 ranges· showing 25
VendorProductVersion rangeFixed in
debianlinux< linux 6.17.8-1 (forky)linux 6.17.8-1 (forky)
linuxlinux
linuxlinux>= 433042a91f9373241307725b52de573933ffedbf < 939c4e33005e2a56ea8fcedddf0da92df864bd3b939c4e33005e2a56ea8fcedddf0da92df864bd3b
linuxlinux>= 4f1fffa2376922f3d1d506e49c0fd445b023a28e < 327f89c21601ebb7889f8c97754b76f08ce95a0c327f89c21601ebb7889f8c97754b76f08ce95a0c
linuxlinux>= 4f1fffa2376922f3d1d506e49c0fd445b023a28e < b556c278d43f4707a9073ca74d55581b4f279806b556c278d43f4707a9073ca74d55581b4f279806
linuxlinux>= 4f1fffa2376922f3d1d506e49c0fd445b023a28e < 5c76f9961c170552c1d07c830b5e1454751516005c76f9961c170552c1d07c830b5e145475151600
linuxlinux>= 6.6.32 < 6.6.1176.6.117
linuxlinux_kernel>= 0 < 6.12.63-16.12.63-1
linuxlinux_kernel>= 0 < 6.17.8-16.17.8-1
linuxlinux_kernel>= 0 < 6.6.1176.6.117
linuxlinux_kernel>= 0 < 6.8.0-106.1066.8.0-106.106
linuxlinux_kernel>= 0 < 6.17.0-14.146.17.0-14.14
linuxlinux_kernel>= 6.7.0 < 6.12.586.12.58
linuxlinux_kernel>= 6.8.0 < 6.17.86.17.8
msrcazl3_libconfuse_3.3-2_on_azure_linux_3.0
msrcazure_linux_3.0_arm
msrcazure_linux_3.0_x64
msrccbl2_libconfuse_3.3-2_on_cbl_mariner_2.0
msrccbl_mariner_1.0_arm
msrccbl_mariner_1.0_x64
msrccbl_mariner_2.0_arm
msrccbl_mariner_2.0_x64
msrccm1_libconfuse_3.3-2_on_cbl_mariner_1.0
ubuntulinux-aws
ubuntulinux-oracle

CVSS provenance

nvdv3.19.8CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
osv3.2LOW
vendor_msrc8.8HIGH
vendor_ubuntu7.8HIGH
vendor_redhat6.3MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.