cbcvebase.
CVE-2025-68372
published 2025-12-24

CVE-2025-68372: In the Linux kernel, the following vulnerability has been resolved: nbd: defer config put in recv_work There is one uaf issue in recv_work when running…

PriorityP420high7.8
EPSS
0.17%
6.8th percentile
In the Linux kernel, the following vulnerability has been resolved: nbd: defer config put in recv_work There is one uaf issue in recv_work when running NBD_CLEAR_SOCK and NBD_CMD_RECONFIGURE: nbd_genl_connect // conf_ref=2 (connect and recv_work A) nbd_open // conf_ref=3 recv_work A done // conf_ref=2 NBD_CLEAR_SOCK // conf_ref=1 nbd_genl_reconfigure // conf_ref=2 (trigger recv_work B) close nbd // conf_ref=1 recv_work B config_put // conf_ref=0 atomic_dec(&config->recv_threads); -> UAF Or only running NBD_CLEAR_SOCK: nbd_genl_connect // conf_ref=2 nbd_open // conf_ref=3 NBD_CLEAR_SOCK // conf_ref=2 close nbd nbd_release config_put // conf_ref=1 recv_work config_put // conf_ref=0 atomic_dec(&config->recv_threads); -> UAF Commit 87aac3a80af5 ("nbd: call nbd_config_put() before notifying the waiter") moved nbd_config_put() to run before waking up the waiter in recv_work, in order to ensure that nbd_start_device_ioctl() would not be woken up while nbd->task_recv was still uncleared. However, in nbd_start_device_ioctl(), after being woken up it explicitly calls flush_workqueue() to make sure all current works are finished. Therefore, there is no need to move the config put ahead of the wakeup. Move nbd_config_put() to the end of recv_work, so that the reference is held for the whole lifetime of the worker thread. This makes sure the config cannot be freed while recv_work is still running, even if clear + reconfigure interleave. In addition, we don't need to worry about recv_work dropping the last nbd_put (which causes deadlock): path A (netlink with NBD_CFLAG_DESTROY_ON_DISCONNECT): connect // nbd_refs=1 (trigger recv_work) open nbd // nbd_refs=2 NBD_CLEAR_SOCK close nbd nbd_release nbd_disconnect_and_put flush_workqueue // recv_work done nbd_config_put nbd_put // nbd_refs=1 nbd_put // nbd_refs=0 queue_work path B (netlink without NBD_CFLAG_DESTROY_ON_DISCONNECT): connect // nbd_refs=2 (trigger recv_work) open nbd // nbd_refs=3 NBD_CLEAR_SOCK // conf_refs=2 clo

Affected

56 ranges· showing 25
VendorProductVersion rangeFixed in
debianlinux< linux 6.1.162-1 (bookworm)linux 6.1.162-1 (bookworm)
debianlinux-6.1< linux 6.1.162-1 (bookworm)linux 6.1.162-1 (bookworm)
linuxlinux
linuxlinux
linuxlinux
linuxlinux
linuxlinux
linuxlinux>= 4.14.204 < 4.154.15
linuxlinux>= 4.19.155 < 4.204.20
linuxlinux>= 5.4.75 < 5.55.5
linuxlinux>= 5.9.5 < 5.105.10
linuxlinux>= 87aac3a80af5cbad93e63250e8a1e19095ba0d30 < 198aa230a6f8c1f6af7ed26b29180749c3e79e4d198aa230a6f8c1f6af7ed26b29180749c3e79e4d
linuxlinux>= 87aac3a80af5cbad93e63250e8a1e19095ba0d30 < d3ba312675911ff9e3fefefd551751e153a9f0a9d3ba312675911ff9e3fefefd551751e153a9f0a9
linuxlinux>= 87aac3a80af5cbad93e63250e8a1e19095ba0d30 < 3692884bd6187d89d41eef81e5a9724519fd01c13692884bd6187d89d41eef81e5a9724519fd01c1
linuxlinux>= 87aac3a80af5cbad93e63250e8a1e19095ba0d30 < 1ba2ced2bbdf7e64a30c3e88c70ea8bc208d15091ba2ced2bbdf7e64a30c3e88c70ea8bc208d1509
linuxlinux>= 87aac3a80af5cbad93e63250e8a1e19095ba0d30 < 6b69593f72e1bfba6ca47ca8d9b619341fded7d66b69593f72e1bfba6ca47ca8d9b619341fded7d6
linuxlinux>= 87aac3a80af5cbad93e63250e8a1e19095ba0d30 < 443a1721806b6ff6303b5229e9811d68172d622f443a1721806b6ff6303b5229e9811d68172d622f
linuxlinux>= 87aac3a80af5cbad93e63250e8a1e19095ba0d30 < 742012f6bf29553fdc460bf646a58df3a7b43d01742012f6bf29553fdc460bf646a58df3a7b43d01
linuxlinux>= 87aac3a80af5cbad93e63250e8a1e19095ba0d30 < 9517b82d8d422d426a988b213fdd45c6b417b86d9517b82d8d422d426a988b213fdd45c6b417b86d
linuxlinux_kernel>= 0 < 5.10.249-15.10.249-1
linuxlinux_kernel>= 0 < 6.1.162-16.1.162-1
linuxlinux_kernel>= 0 < 6.12.63-16.12.63-1
linuxlinux_kernel>= 0 < 6.17.13-16.17.13-1
linuxlinux_kernel>= 0 < 5.15.0-173.1835.15.0-173.183
linuxlinux_kernel>= 0 < 6.17.0-19.196.17.0-19.19

CVSS provenance

osv7.8HIGH
vendor_ubuntu7.8HIGH
vendor_msrc5.5MEDIUM
vendor_redhat5.5MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.