cbcvebase.
CVE-2025-40328
published 2025-12-09

CVE-2025-40328: In the Linux kernel, the following vulnerability has been resolved: smb: client: fix potential UAF in smb2_close_cached_fid() find_or_create_cached_dir() could…

PriorityP343high8.8CVSS 3.1
AVNACLPRNUIRSUCHIHAH
EPSS
0.40%
32.6th percentile
In the Linux kernel, the following vulnerability has been resolved: smb: client: fix potential UAF in smb2_close_cached_fid() find_or_create_cached_dir() could grab a new reference after kref_put() had seen the refcount drop to zero but before cfid_list_lock is acquired in smb2_close_cached_fid(), leading to use-after-free. Switch to kref_put_lock() so cfid_release() is called with cfid_list_lock held, closing that gap.

Affected

17 ranges
VendorProductVersion rangeFixed in
debianlinux< linux 6.17.8-1 (forky)linux 6.17.8-1 (forky)
linuxlinux
linuxlinux>= ebe98f1447bbccf8228335c62d86af02a0ed23f7 < cb52d9c86d70298de0ab7c7953653898cbc0efd6cb52d9c86d70298de0ab7c7953653898cbc0efd6
linuxlinux>= ebe98f1447bbccf8228335c62d86af02a0ed23f7 < 065bd62412271a2d734810dd50336cae88c54427065bd62412271a2d734810dd50336cae88c54427
linuxlinux>= ebe98f1447bbccf8228335c62d86af02a0ed23f7 < bdb596ceb4b7c3f28786a33840263728217fbcf5bdb596ceb4b7c3f28786a33840263728217fbcf5
linuxlinux>= ebe98f1447bbccf8228335c62d86af02a0ed23f7 < 734e99623c5b65bf2c03e35978a0b980ebc3c2f8734e99623c5b65bf2c03e35978a0b980ebc3c2f8
linuxlinux_kernel>= 0 < 6.12.63-16.12.63-1
linuxlinux_kernel>= 0 < 6.17.8-16.17.8-1
linuxlinux_kernel>= 0 < 6.8.0-106.1066.8.0-106.106
linuxlinux_kernel>= 0 < 6.17.0-14.146.17.0-14.14
linuxlinux_kernel>= 6.1.0 < 6.6.1176.6.117
linuxlinux_kernel>= 6.13.0 < 6.17.86.17.8
linuxlinux_kernel>= 6.7.0 < 6.12.586.12.58
msrcazl3_kernel_6.6.112.1-2_on_azure_linux_3.0
ubuntulinux-aws
ubuntulinux-oracle
ubuntulinux-xilinx

CVSS provenance

nvdv3.18.8HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
osv3.2LOW
vendor_ubuntu7.8HIGH
vendor_msrc7.0HIGH
vendor_redhat7.0MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.