{
"dataType": "CVE_RECORD",
"dataVersion": "5.2",
"cveMetadata": {
"cveId": "CVE-2025-38379",
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"state": "PUBLISHED",
"assignerShortName": "Linux",
"dateReserved": "2025-04-16T04:51:24.010Z",
"datePublished": "2025-07-25T12:53:21.098Z",
"dateUpdated": "2026-08-05T12:01:28.794Z"
},
"containers": {
"cna": {
"providerMetadata": {
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux",
"dateUpdated": "2026-08-05T12:01:28.794Z"
},
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\nsmb: client: fix warning when reconnecting channel\n\nWhen reconnecting a channel in smb2_reconnect_server(), a dummy tcon\nis passed down to smb2_reconnect() with ->query_interface\nuninitialized, so we can't call queue_delayed_work() on it.\n\nFix the following warning by ensuring that we're queueing the delayed\nworker from correct tcon.\n\nWARNING: CPU: 4 PID: 1126 at kernel/workqueue.c:2498 __queue_delayed_work+0x1d2/0x200\nModules linked in: cifs cifs_arc4 nls_ucs2_utils cifs_md4 [last unloaded: cifs]\nCPU: 4 UID: 0 PID: 1126 Comm: kworker/4:0 Not tainted 6.16.0-rc3 #5 PREEMPT(voluntary)\nHardware name: QEMU Standard PC (Q35 + ICH9, 2009), BIOS 1.16.3-4.fc42 04/01/2014\nWorkqueue: cifsiod smb2_reconnect_server [cifs]\nRIP: 0010:__queue_delayed_work+0x1d2/0x200\nCode: 41 5e 41 5f e9 7f ee ff ff 90 0f 0b 90 e9 5d ff ff ff bf 02 00\n00 00 e8 6c f3 07 00 89 c3 eb bd 90 0f 0b 90 e9 57 f> 0b 90 e9 65 fe\nff ff 90 0f 0b 90 e9 72 fe ff ff 90 0f 0b 90 e9\nRSP: 0018:ffffc900014afad8 EFLAGS: 00010003\nRAX: 0000000000000000 RBX: ffff888124d99988 RCX: ffffffff81399cc1\nRDX: dffffc0000000000 RSI: ffff888114326e00 RDI: ffff888124d999f0\nRBP: 000000000000ea60 R08: 0000000000000001 R09: ffffed10249b3331\nR10: ffff888124d9998f R11: 0000000000000004 R12: 0000000000000040\nR13: ffff888114326e00 R14: ffff888124d999d8 R15: ffff888114939020\nFS: 0000000000000000(0000) GS:ffff88829f7fe000(0000) knlGS:0000000000000000\nCS: 0010 DS: 0000 ES: 0000 CR0: 0000000080050033\nCR2: 00007ffe7a2b4038 CR3: 0000000120a6f000 CR4: 0000000000750ef0\nPKRU: 55555554\nCall Trace:\n \n queue_delayed_work_on+0xb4/0xc0\n smb2_reconnect+0xb22/0xf50 [cifs]\n smb2_reconnect_server+0x413/0xd40 [cifs]\n ? __pfx_smb2_reconnect_server+0x10/0x10 [cifs]\n ? local_clock_noinstr+0xd/0xd0\n ? local_clock+0x15/0x30\n ? lock_release+0x29b/0x390\n process_one_work+0x4c5/0xa10\n ? __pfx_process_one_work+0x10/0x10\n ? __list_add_valid_or_report+0x37/0x120\n worker_thread+0x2f1/0x5a0\n ? __kthread_parkme+0xde/0x100\n ? __pfx_worker_thread+0x10/0x10\n kthread+0x1fe/0x380\n ? kthread+0x10f/0x380\n ? __pfx_kthread+0x10/0x10\n ? local_clock_noinstr+0xd/0xd0\n ? ret_from_fork+0x1b/0x1f0\n ? local_clock+0x15/0x30\n ? lock_release+0x29b/0x390\n ? rcu_is_watching+0x20/0x50\n ? __pfx_kthread+0x10/0x10\n ret_from_fork+0x15b/0x1f0\n ? __pfx_kthread+0x10/0x10\n ret_from_fork_asm+0x1a/0x30\n \nirq event stamp: 1116206\nhardirqs last enabled at (1116205): [] __up_console_sem+0x52/0x60\nhardirqs last disabled at (1116206): [] queue_delayed_work_on+0x6e/0xc0\nsoftirqs last enabled at (1116138): [] __smb_send_rqst+0x42d/0x950 [cifs]\nsoftirqs last disabled at (1116136): [] release_sock+0x21/0xf0"
}
],
"metrics": [
{
"cvssV3_1": {
"version": "3.1",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
"baseScore": 7.5,
"baseSeverity": "HIGH"
},
"scenarios": [
{
"lang": "en",
"value": "AV:N - The faulty path is driven entirely by a remote SMB server over TCP/445 — the server sets `SMB2_GLOBAL_CAP_MULTI_CHANNEL` in its NEGOTIATE response and drops the connection to force `smb2_reconnect_server()` to run. An off-path attacker able to inject TCP resets against an existing mount can equally force the reconnect.\nAC:L - Both preconditions are attacker-controlled and deterministic: advertise the multichannel capability bit, then close the TCP connection. The IPC tcon always has an uninitialized `query_interfaces` worker, so the WARN is hit on the first reconnect with no race or memory-layout dependency.\nPR:N - The attacker is the remote SMB server (or a malicious/compromised server the client connects to) and holds no credentials or privileges on the victim system; the capability advertisement is read from the unauthenticated NEGOTIATE response and the reconnect path is reached before any per-request authorization on the client.\nUI:N - The share is already mounted as a standing configuration (fstab/automount/persistent mount), and the trigger is a server-initiated disconnect handled by the `cifsiod` workqueue. No action by a local user is required at attack time.\nS:U - The fault is confined to the cifs client's own workqueue/timer bookkeeping inside the kernel; no VM, IOMMU, or sandbox boundary is crossed.\nC:N - No memory is read out of bounds and no freed object is reused — the timer is rejected by the `!timer->function` shutdown guard before enqueue. The only output is a WARN backtrace to the privileged kernel log, which the remote attacker cannot read.\nI:N - The only writes are to fields inside the tcon's own embedded `delayed_work` (`dwork->wq`, `dwork->cpu`, `timer->expires`) and the `WORK_STRUCT_PENDING` bit; nothing is written out of bounds or to freed memory, so no kernel data or control flow can be modified.\nA:H - A remote server reliably triggers a kernel WARN/oops splat at `kernel/workqueue.c:2498`, tainting the kernel — and on the many deployments booted with `panic_on_warn` (Android, ChromeOS, hardened cloud fleets) this is an immediate remote kernel panic. It additionally leaves the work item permanently marked PENDING, breaking multichannel interface polling for that connection."
}
]
}
],
"affected": [
{
"product": "Linux",
"vendor": "Linux",
"defaultStatus": "unaffected",
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"programFiles": [
"fs/smb/client/cifsglob.h",
"fs/smb/client/smb2pdu.c"
],
"versions": [
{
"version": "202d7e838967dda02855cd925db7fd8c52c56af7",
"lessThan": "0cee638d92ac898d73eccc4e4bab70e9fc95946a",
"status": "affected",
"versionType": "git"
},
{
"version": "2c34f1e095a12be3674fb79d84d1af7896e49245",
"lessThan": "3f6932ef25378794894c3c1024092ad14da2d330",
"status": "affected",
"versionType": "git"
},
{
"version": "4f81ee0af2b8c4089e308f7cb6b5ea5a4efe5b94",
"lessThan": "9d2b629a9dc5c72537645533af1cb11a7d34c4b1",
"status": "affected",
"versionType": "git"
},
{
"version": "42ca547b13a20e7cbb04fbdf8d5f089ac4bb35b7",
"lessThan": "3bbe46716092d8ef6b0df4b956f585c5cd0fc78e",
"status": "affected",
"versionType": "git"
}
]
},
{
"product": "Linux",
"vendor": "Linux",
"defaultStatus": "unaffected",
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"programFiles": [
"fs/smb/client/cifsglob.h",
"fs/smb/client/smb2pdu.c"
],
"versions": [
{
"version": "6.6.95",
"lessThan": "6.6.97",
"status": "affected",
"versionType": "semver"
},
{
"version": "6.12.35",
"lessThan": "6.12.37",
"status": "affected",
"versionType": "semver"
},
{
"version": "6.15.4",
"lessThan": "6.15.6",
"status": "affected",
"versionType": "semver"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"operator": "OR",
"negate": false,
"cpeMatch": [
{
"vulnerable": true,
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionStartIncluding": "6.6.95",
"versionEndExcluding": "6.6.97"
},
{
"vulnerable": true,
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionStartIncluding": "6.12.35",
"versionEndExcluding": "6.12.37"
},
{
"vulnerable": true,
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionStartIncluding": "6.15.4",
"versionEndExcluding": "6.15.6"
}
]
}
]
}
],
"references": [
{
"url": "https://git.kernel.org/stable/c/0cee638d92ac898d73eccc4e4bab70e9fc95946a"
},
{
"url": "https://git.kernel.org/stable/c/3f6932ef25378794894c3c1024092ad14da2d330"
},
{
"url": "https://git.kernel.org/stable/c/9d2b629a9dc5c72537645533af1cb11a7d34c4b1"
},
{
"url": "https://git.kernel.org/stable/c/3bbe46716092d8ef6b0df4b956f585c5cd0fc78e"
}
],
"title": "smb: client: fix warning when reconnecting channel",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
}
}