{ "dataType": "CVE_RECORD", "dataVersion": "5.2", "cveMetadata": { "cveId": "CVE-2025-38321", "assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67", "state": "PUBLISHED", "assignerShortName": "Linux", "dateReserved": "2025-04-16T04:51:24.004Z", "datePublished": "2025-07-10T08:14:57.046Z", "dateUpdated": "2026-08-05T12:01:08.577Z" }, "containers": { "cna": { "providerMetadata": { "orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67", "shortName": "Linux", "dateUpdated": "2026-08-05T12:01:08.577Z" }, "descriptions": [ { "lang": "en", "value": "In the Linux kernel, the following vulnerability has been resolved:\n\nsmb: Log an error when close_all_cached_dirs fails\n\nUnder low-memory conditions, close_all_cached_dirs() can't move the\ndentries to a separate list to dput() them once the locks are dropped.\nThis will result in a \"Dentry still in use\" error, so add an error\nmessage that makes it clear this is what happened:\n\n[ 495.281119] CIFS: VFS: \\\\otters.example.com\\share Out of memory while dropping dentries\n[ 495.281595] ------------[ cut here ]------------\n[ 495.281887] BUG: Dentry ffff888115531138{i=78,n=/} still in use (2) [unmount of cifs cifs]\n[ 495.282391] WARNING: CPU: 1 PID: 2329 at fs/dcache.c:1536 umount_check+0xc8/0xf0\n\nAlso, bail out of looping through all tcons as soon as a single\nallocation fails, since we're already in trouble, and kmalloc() attempts\nfor subseqeuent tcons are likely to fail just like the first one did." } ], "metrics": [ { "cvssV3_1": { "version": "3.1", "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H", "baseScore": 7.8, "baseSeverity": "HIGH" }, "scenarios": [ { "lang": "en", "value": "AV:L - The vulnerable code runs only in `cifs_kill_sb()` on the local unmount path, and the triggering condition is a local GFP_ATOMIC allocation failure under memory pressure; a remote SMB server can influence how many cached dirs exist but cannot drive the unmount or the OOM.\nAC:L - Memory pressure is directly attacker-inducible and GFP_ATOMIC allocations fail readily under it, and the mount/unmount cycle can be repeated indefinitely, with up to `max_cached_dirs` allocations per tcon per unmount (multiplied further by `multiuser` mounts) giving many independent chances to hit the failure.\nPR:L - A basic unprivileged local account suffices to create the memory pressure, and the unmount is reachable to the same user through the standard `user`/`users` fstab option for SMB shares, setuid `mount.cifs`, or an autofs/systemd idle-expiry unmount; no root or CAP_SYS_ADMIN in the init namespace is required.\nUI:N - On user-mountable shares the attacker performs the mount, the memory exhaustion, and the unmount entirely from their own process, and on automounted shares the expiry unmount happens on a timer with no victim action at all.\nS:U - The leaked dentries, poisoned inodes, and freed superblock are all kernel objects within the same security authority; no VM, IOMMU, or sandbox boundary is crossed.\nC:H - When the tcon is shared with a surviving superblock, the undropped `cfid->dentry` outlives `destroy_super()`, so the later `dput()` reads `dentry->d_sb` fields (`s_dentry_lru`, `s_d_op`, `s_type`) out of a freed kmalloc-2k object the attacker can reoccupy, giving a use-after-free read primitive over sprayed heap contents.\nI:H - The same dangling `dput()` performs list operations on the freed superblock's `s_dentry_lru`, writing into attacker-groomed heap memory, and the VFS additionally overwrites `i_op`/`i_sb`/`i_mapping` of the still-referenced inodes — a use-after-free write primitive usable for control-flow corruption.\nA:H - The failure deterministically produces `WARN(1, \"BUG: Dentry ... still in use\")` in `umount_check()` (a panic under `panic_on_warn`), then `CHECK_DATA_CORRUPTION()` on busy inodes which is an outright `BUG()` with `CONFIG_BUG_ON_DATA_CORRUPTION=y`, and otherwise poisons the inodes so the subsequent `iput_final()` oopses on `VFS_PTR_POISON`." } ] } ], "affected": [ { "product": "Linux", "vendor": "Linux", "defaultStatus": "unaffected", "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git", "programFiles": [ "fs/smb/client/cached_dir.c" ], "versions": [ { "version": "73934e535cffbda1490fa97d82690a0f9aa73e94", "lessThan": "b8ced2b9a23a1a2c1e0ed8d0d02512e51bdf38da", "status": "affected", "versionType": "git" }, { "version": "548812afd96982a76a93ba76c0582ea670c40d9e", "lessThan": "43f26094d6702e494e800532c3f1606e7a68eb30", "status": "affected", "versionType": "git" }, { "version": "3fa640d035e5ae526769615c35cb9ed4be6e3662", "lessThan": "4479db143390bdcadc1561292aab579cdfa9f6c6", "status": "affected", "versionType": "git" }, { "version": "3fa640d035e5ae526769615c35cb9ed4be6e3662", "lessThan": "a2182743a8b4969481f64aec4908ff162e8a206c", "status": "affected", "versionType": "git" }, { "version": "ff4528bbc82d0d90073751f7b49e7b9e9c7e5638", "status": "affected", "versionType": "git" }, { "version": "6.6.64", "lessThan": "6.6.95", "status": "affected", "versionType": "semver" }, { "version": "6.12.2", "lessThan": "6.12.35", "status": "affected", "versionType": "semver" }, { "version": "6.11.11", "lessThan": "6.12", "status": "affected", "versionType": "semver" } ] }, { "product": "Linux", "vendor": "Linux", "defaultStatus": "affected", "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git", "programFiles": [ "fs/smb/client/cached_dir.c" ], "versions": [ { "version": "6.13", "status": "affected" }, { "version": "0", "lessThan": "6.13", "status": "unaffected", "versionType": "semver" }, { "version": "6.6.95", "lessThanOrEqual": "6.6.*", "status": "unaffected", "versionType": "semver" }, { "version": "6.12.35", "lessThanOrEqual": "6.12.*", "status": "unaffected", "versionType": "semver" }, { "version": "6.15.4", "lessThanOrEqual": "6.15.*", "status": "unaffected", "versionType": "semver" }, { "version": "6.16", "lessThanOrEqual": "*", "status": "unaffected", "versionType": "original_commit_for_fix" } ] } ], "cpeApplicability": [ { "nodes": [ { "operator": "OR", "negate": false, "cpeMatch": [ { "vulnerable": true, "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*", "versionStartIncluding": "6.6.64", "versionEndExcluding": "6.6.95" }, { "vulnerable": true, "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*", "versionStartIncluding": "6.12.2", "versionEndExcluding": "6.12.35" }, { "vulnerable": true, "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*", "versionStartIncluding": "6.13", "versionEndExcluding": "6.15.4" }, { "vulnerable": true, "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*", "versionStartIncluding": "6.13", "versionEndExcluding": "6.16" }, { "vulnerable": true, "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*", "versionStartIncluding": "6.11.11" } ] } ] } ], "references": [ { "url": "https://git.kernel.org/stable/c/b8ced2b9a23a1a2c1e0ed8d0d02512e51bdf38da" }, { "url": "https://git.kernel.org/stable/c/43f26094d6702e494e800532c3f1606e7a68eb30" }, { "url": "https://git.kernel.org/stable/c/4479db143390bdcadc1561292aab579cdfa9f6c6" }, { "url": "https://git.kernel.org/stable/c/a2182743a8b4969481f64aec4908ff162e8a206c" } ], "title": "smb: Log an error when close_all_cached_dirs fails", "x_generator": { "engine": "bippy-1.2.0" } } } }