{ "dataType": "CVE_RECORD", "dataVersion": "5.2", "cveMetadata": { "cveId": "CVE-2025-38379", "assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67", "state": "PUBLISHED", "assignerShortName": "Linux", "dateReserved": "2025-04-16T04:51:24.010Z", "datePublished": "2025-07-25T12:53:21.098Z", "dateUpdated": "2026-08-05T12:01:28.794Z" }, "containers": { "cna": { "providerMetadata": { "orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67", "shortName": "Linux", "dateUpdated": "2026-08-05T12:01:28.794Z" }, "descriptions": [ { "lang": "en", "value": "In the Linux kernel, the following vulnerability has been resolved:\n\nsmb: client: fix warning when reconnecting channel\n\nWhen reconnecting a channel in smb2_reconnect_server(), a dummy tcon\nis passed down to smb2_reconnect() with ->query_interface\nuninitialized, so we can't call queue_delayed_work() on it.\n\nFix the following warning by ensuring that we're queueing the delayed\nworker from correct tcon.\n\nWARNING: CPU: 4 PID: 1126 at kernel/workqueue.c:2498 __queue_delayed_work+0x1d2/0x200\nModules linked in: cifs cifs_arc4 nls_ucs2_utils cifs_md4 [last unloaded: cifs]\nCPU: 4 UID: 0 PID: 1126 Comm: kworker/4:0 Not tainted 6.16.0-rc3 #5 PREEMPT(voluntary)\nHardware name: QEMU Standard PC (Q35 + ICH9, 2009), BIOS 1.16.3-4.fc42 04/01/2014\nWorkqueue: cifsiod smb2_reconnect_server [cifs]\nRIP: 0010:__queue_delayed_work+0x1d2/0x200\nCode: 41 5e 41 5f e9 7f ee ff ff 90 0f 0b 90 e9 5d ff ff ff bf 02 00\n00 00 e8 6c f3 07 00 89 c3 eb bd 90 0f 0b 90 e9 57 f> 0b 90 e9 65 fe\nff ff 90 0f 0b 90 e9 72 fe ff ff 90 0f 0b 90 e9\nRSP: 0018:ffffc900014afad8 EFLAGS: 00010003\nRAX: 0000000000000000 RBX: ffff888124d99988 RCX: ffffffff81399cc1\nRDX: dffffc0000000000 RSI: ffff888114326e00 RDI: ffff888124d999f0\nRBP: 000000000000ea60 R08: 0000000000000001 R09: ffffed10249b3331\nR10: ffff888124d9998f R11: 0000000000000004 R12: 0000000000000040\nR13: ffff888114326e00 R14: ffff888124d999d8 R15: ffff888114939020\nFS: 0000000000000000(0000) GS:ffff88829f7fe000(0000) knlGS:0000000000000000\nCS: 0010 DS: 0000 ES: 0000 CR0: 0000000080050033\nCR2: 00007ffe7a2b4038 CR3: 0000000120a6f000 CR4: 0000000000750ef0\nPKRU: 55555554\nCall Trace:\n \n queue_delayed_work_on+0xb4/0xc0\n smb2_reconnect+0xb22/0xf50 [cifs]\n smb2_reconnect_server+0x413/0xd40 [cifs]\n ? __pfx_smb2_reconnect_server+0x10/0x10 [cifs]\n ? local_clock_noinstr+0xd/0xd0\n ? local_clock+0x15/0x30\n ? lock_release+0x29b/0x390\n process_one_work+0x4c5/0xa10\n ? __pfx_process_one_work+0x10/0x10\n ? __list_add_valid_or_report+0x37/0x120\n worker_thread+0x2f1/0x5a0\n ? __kthread_parkme+0xde/0x100\n ? __pfx_worker_thread+0x10/0x10\n kthread+0x1fe/0x380\n ? kthread+0x10f/0x380\n ? __pfx_kthread+0x10/0x10\n ? local_clock_noinstr+0xd/0xd0\n ? ret_from_fork+0x1b/0x1f0\n ? local_clock+0x15/0x30\n ? lock_release+0x29b/0x390\n ? rcu_is_watching+0x20/0x50\n ? __pfx_kthread+0x10/0x10\n ret_from_fork+0x15b/0x1f0\n ? __pfx_kthread+0x10/0x10\n ret_from_fork_asm+0x1a/0x30\n \nirq event stamp: 1116206\nhardirqs last enabled at (1116205): [] __up_console_sem+0x52/0x60\nhardirqs last disabled at (1116206): [] queue_delayed_work_on+0x6e/0xc0\nsoftirqs last enabled at (1116138): [] __smb_send_rqst+0x42d/0x950 [cifs]\nsoftirqs last disabled at (1116136): [] release_sock+0x21/0xf0" } ], "metrics": [ { "cvssV3_1": { "version": "3.1", "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", "baseScore": 7.5, "baseSeverity": "HIGH" }, "scenarios": [ { "lang": "en", "value": "AV:N - The faulty path is driven entirely by a remote SMB server over TCP/445 — the server sets `SMB2_GLOBAL_CAP_MULTI_CHANNEL` in its NEGOTIATE response and drops the connection to force `smb2_reconnect_server()` to run. An off-path attacker able to inject TCP resets against an existing mount can equally force the reconnect.\nAC:L - Both preconditions are attacker-controlled and deterministic: advertise the multichannel capability bit, then close the TCP connection. The IPC tcon always has an uninitialized `query_interfaces` worker, so the WARN is hit on the first reconnect with no race or memory-layout dependency.\nPR:N - The attacker is the remote SMB server (or a malicious/compromised server the client connects to) and holds no credentials or privileges on the victim system; the capability advertisement is read from the unauthenticated NEGOTIATE response and the reconnect path is reached before any per-request authorization on the client.\nUI:N - The share is already mounted as a standing configuration (fstab/automount/persistent mount), and the trigger is a server-initiated disconnect handled by the `cifsiod` workqueue. No action by a local user is required at attack time.\nS:U - The fault is confined to the cifs client's own workqueue/timer bookkeeping inside the kernel; no VM, IOMMU, or sandbox boundary is crossed.\nC:N - No memory is read out of bounds and no freed object is reused — the timer is rejected by the `!timer->function` shutdown guard before enqueue. The only output is a WARN backtrace to the privileged kernel log, which the remote attacker cannot read.\nI:N - The only writes are to fields inside the tcon's own embedded `delayed_work` (`dwork->wq`, `dwork->cpu`, `timer->expires`) and the `WORK_STRUCT_PENDING` bit; nothing is written out of bounds or to freed memory, so no kernel data or control flow can be modified.\nA:H - A remote server reliably triggers a kernel WARN/oops splat at `kernel/workqueue.c:2498`, tainting the kernel — and on the many deployments booted with `panic_on_warn` (Android, ChromeOS, hardened cloud fleets) this is an immediate remote kernel panic. It additionally leaves the work item permanently marked PENDING, breaking multichannel interface polling for that connection." } ] } ], "affected": [ { "product": "Linux", "vendor": "Linux", "defaultStatus": "unaffected", "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git", "programFiles": [ "fs/smb/client/cifsglob.h", "fs/smb/client/smb2pdu.c" ], "versions": [ { "version": "202d7e838967dda02855cd925db7fd8c52c56af7", "lessThan": "0cee638d92ac898d73eccc4e4bab70e9fc95946a", "status": "affected", "versionType": "git" }, { "version": "2c34f1e095a12be3674fb79d84d1af7896e49245", "lessThan": "3f6932ef25378794894c3c1024092ad14da2d330", "status": "affected", "versionType": "git" }, { "version": "4f81ee0af2b8c4089e308f7cb6b5ea5a4efe5b94", "lessThan": "9d2b629a9dc5c72537645533af1cb11a7d34c4b1", "status": "affected", "versionType": "git" }, { "version": "42ca547b13a20e7cbb04fbdf8d5f089ac4bb35b7", "lessThan": "3bbe46716092d8ef6b0df4b956f585c5cd0fc78e", "status": "affected", "versionType": "git" } ] }, { "product": "Linux", "vendor": "Linux", "defaultStatus": "unaffected", "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git", "programFiles": [ "fs/smb/client/cifsglob.h", "fs/smb/client/smb2pdu.c" ], "versions": [ { "version": "6.6.95", "lessThan": "6.6.97", "status": "affected", "versionType": "semver" }, { "version": "6.12.35", "lessThan": "6.12.37", "status": "affected", "versionType": "semver" }, { "version": "6.15.4", "lessThan": "6.15.6", "status": "affected", "versionType": "semver" } ] } ], "cpeApplicability": [ { "nodes": [ { "operator": "OR", "negate": false, "cpeMatch": [ { "vulnerable": true, "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*", "versionStartIncluding": "6.6.95", "versionEndExcluding": "6.6.97" }, { "vulnerable": true, "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*", "versionStartIncluding": "6.12.35", "versionEndExcluding": "6.12.37" }, { "vulnerable": true, "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*", "versionStartIncluding": "6.15.4", "versionEndExcluding": "6.15.6" } ] } ] } ], "references": [ { "url": "https://git.kernel.org/stable/c/0cee638d92ac898d73eccc4e4bab70e9fc95946a" }, { "url": "https://git.kernel.org/stable/c/3f6932ef25378794894c3c1024092ad14da2d330" }, { "url": "https://git.kernel.org/stable/c/9d2b629a9dc5c72537645533af1cb11a7d34c4b1" }, { "url": "https://git.kernel.org/stable/c/3bbe46716092d8ef6b0df4b956f585c5cd0fc78e" } ], "title": "smb: client: fix warning when reconnecting channel", "x_generator": { "engine": "bippy-1.2.0" } } } }