{"dataType":"CVE_RECORD","dataVersion":"5.2","cveMetadata":{"cveId":"CVE-2025-21673","assignerOrgId":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","state":"PUBLISHED","assignerShortName":"Linux","dateReserved":"2024-12-29T08:45:45.736Z","datePublished":"2025-01-31T11:25:35.922Z","dateUpdated":"2026-08-05T11:53:31.173Z"},"containers":{"cna":{"providerMetadata":{"orgId":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","shortName":"Linux","dateUpdated":"2026-08-05T11:53:31.173Z"},"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nsmb: client: fix double free of TCP_Server_Info::hostname\n\nWhen shutting down the server in cifs_put_tcp_session(), cifsd thread\nmight be reconnecting to multiple DFS targets before it realizes it\nshould exit the loop, so @server->hostname can't be freed as long as\ncifsd thread isn't done.  Otherwise the following can happen:\n\n  RIP: 0010:__slab_free+0x223/0x3c0\n  Code: 5e 41 5f c3 cc cc cc cc 4c 89 de 4c 89 cf 44 89 44 24 08 4c 89\n  1c 24 e8 fb cf 8e 00 44 8b 44 24 08 4c 8b 1c 24 e9 5f fe ff ff <0f>\n  0b 41 f7 45 08 00 0d 21 00 0f 85 2d ff ff ff e9 1f ff ff ff 80\n  RSP: 0018:ffffb26180dbfd08 EFLAGS: 00010246\n  RAX: ffff8ea34728e510 RBX: ffff8ea34728e500 RCX: 0000000000800068\n  RDX: 0000000000800068 RSI: 0000000000000000 RDI: ffff8ea340042400\n  RBP: ffffe112041ca380 R08: 0000000000000001 R09: 0000000000000000\n  R10: 6170732e31303000 R11: 70726f632e786563 R12: ffff8ea34728e500\n  R13: ffff8ea340042400 R14: ffff8ea34728e500 R15: 0000000000800068\n  FS: 0000000000000000(0000) GS:ffff8ea66fd80000(0000)\n  000000\n  CS:  0010 DS: 0000 ES: 0000 CR0: 0000000080050033\n  CR2: 00007ffc25376080 CR3: 000000012a2ba001 CR4:\n  PKRU: 55555554\n  Call Trace:\n   <TASK>\n   ? show_trace_log_lvl+0x1c4/0x2df\n   ? show_trace_log_lvl+0x1c4/0x2df\n   ? __reconnect_target_unlocked+0x3e/0x160 [cifs]\n   ? __die_body.cold+0x8/0xd\n   ? die+0x2b/0x50\n   ? do_trap+0xce/0x120\n   ? __slab_free+0x223/0x3c0\n   ? do_error_trap+0x65/0x80\n   ? __slab_free+0x223/0x3c0\n   ? exc_invalid_op+0x4e/0x70\n   ? __slab_free+0x223/0x3c0\n   ? asm_exc_invalid_op+0x16/0x20\n   ? __slab_free+0x223/0x3c0\n   ? extract_hostname+0x5c/0xa0 [cifs]\n   ? extract_hostname+0x5c/0xa0 [cifs]\n   ? __kmalloc+0x4b/0x140\n   __reconnect_target_unlocked+0x3e/0x160 [cifs]\n   reconnect_dfs_server+0x145/0x430 [cifs]\n   cifs_handle_standard+0x1ad/0x1d0 [cifs]\n   cifs_demultiplex_thread+0x592/0x730 [cifs]\n   ? __pfx_cifs_demultiplex_thread+0x10/0x10 [cifs]\n   kthread+0xdd/0x100\n   ? __pfx_kthread+0x10/0x10\n   ret_from_fork+0x29/0x50\n   </TASK>"}],"metrics":[{"cvssV3_1":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","baseScore":9.8,"baseSeverity":"CRITICAL"},"scenarios":[{"lang":"en","value":"AV:N - The bug lives in the SMB client's connection/reconnect handling, which processes data from the remote peer — the remote server controls when the TCP connection drops (forcing reconnect) and controls the DFS referral target list that drives the offending free loop. A compromised/malicious SMB-DFS file server, or an on-path attacker able to reset connections and inject referrals, reaches this over the network.\nAC:L - The attacker controls both sides of the race and the window size: it forces reconnects at will, supplies an arbitrarily long DFS target list, and can point targets at blackholed addresses so each `generic_ip_connect()` blocks for the TCP SYN-retry timeout (~130s) while `msleep(3000)` adds more, and the per-target loop never re-checks `tcpStatus`. The race can be retried unboundedly on every reconnect cycle, and it was hit in real-world operation.\nPR:N - The attacking SMB server holds no privileges on the victim client, and the vulnerable `__reconnect_target_unlocked()` path executes during socket reconnect, before SMB negotiate/session-setup — i.e. pre-authentication. The teardown side is likewise reachable via timer/workqueue-driven paths (`smb2_reconnect_server`, automount expiry) requiring no local privileges.\nUI:N - For an already-mounted DFS share (fstab/autofs, the normal enterprise deployment), reconnect, referral failover, and automount expiry are entirely server- and timer-driven, so no victim action occurs during the attack. The existing mount is a precondition of the deployment, not an in-attack user step.\nS:U - The double free corrupts the kernel slab allocator and impacts only kernel-managed resources within the same security authority. No VM, IOMMU, or sandbox boundary is crossed.\nC:H - A double free lets the same slab object be handed to two allocation sites, yielding type confusion and an arbitrary-read primitive. Additionally there is a direct leak: `reconn_set_ipaddr_from_hostname()` formats the freed string into a UNC and passes it to the `dns_query()` userspace upcall, exfiltrating reused kernel heap contents to userspace verbatim.\nI:H - Double free is a classic heap-corruption primitive — freelist manipulation via heap spraying gives a controlled write and enables control-flow hijacking and privilege escalation. The freed object is a small attacker-influenced `kmalloc` string in a heavily-used general-purpose cache, making reclaim straightforward.\nA:H - The reported effect is an immediate slab consistency BUG (`__slab_free` invalid-op) killing the cifsd kthread, and a panic under `panic_on_oops`. Even unexploited, the allocator corruption reliably destabilizes or crashes the whole system."}]}],"affected":[{"product":"Linux","vendor":"Linux","defaultStatus":"unaffected","repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","programFiles":["fs/smb/client/connect.c"],"versions":[{"version":"7be3248f313930ff3d3436d4e9ddbe9fccc1f541","lessThan":"1ea68070338518a1d31ce71e6abfe1b30001b27a","status":"affected","versionType":"git"},{"version":"7be3248f313930ff3d3436d4e9ddbe9fccc1f541","lessThan":"a2be5f2ba34d0c6d5ef2624b24e3d852561fcd6a","status":"affected","versionType":"git"},{"version":"7be3248f313930ff3d3436d4e9ddbe9fccc1f541","lessThan":"fa2f9906a7b333ba757a7dbae0713d8a5396186e","status":"affected","versionType":"git"},{"version":"49f933bb3016269dc50074eac5f6033d127644f1","status":"affected","versionType":"git"},{"version":"1c35a216ef77db708178ca225d796271f2f60a7a","status":"affected","versionType":"git"},{"version":"5.14.19","lessThan":"5.15","status":"affected","versionType":"semver"},{"version":"5.15.3","lessThan":"5.16","status":"affected","versionType":"semver"}]},{"product":"Linux","vendor":"Linux","defaultStatus":"affected","repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","programFiles":["fs/smb/client/connect.c"],"versions":[{"version":"5.16","status":"affected"},{"version":"0","lessThan":"5.16","status":"unaffected","versionType":"semver"},{"version":"6.6.74","lessThanOrEqual":"6.6.*","status":"unaffected","versionType":"semver"},{"version":"6.12.11","lessThanOrEqual":"6.12.*","status":"unaffected","versionType":"semver"},{"version":"6.13","lessThanOrEqual":"*","status":"unaffected","versionType":"original_commit_for_fix"}]}],"cpeApplicability":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"5.16","versionEndExcluding":"6.6.74"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"5.16","versionEndExcluding":"6.12.11"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"5.16","versionEndExcluding":"6.13"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"5.14.19"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"5.15.3"}]}]}],"references":[{"url":"https://git.kernel.org/stable/c/1ea68070338518a1d31ce71e6abfe1b30001b27a"},{"url":"https://git.kernel.org/stable/c/a2be5f2ba34d0c6d5ef2624b24e3d852561fcd6a"},{"url":"https://git.kernel.org/stable/c/fa2f9906a7b333ba757a7dbae0713d8a5396186e"}],"title":"smb: client: fix double free of TCP_Server_Info::hostname","x_generator":{"engine":"bippy-1.2.0"}},"adp":[{"metrics":[{"cvssV3_1":{"scope":"UNCHANGED","version":"3.1","baseScore":5.5,"attackVector":"LOCAL","baseSeverity":"MEDIUM","vectorString":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","integrityImpact":"NONE","userInteraction":"NONE","attackComplexity":"LOW","availabilityImpact":"HIGH","privilegesRequired":"LOW","confidentialityImpact":"NONE"}},{"other":{"type":"ssvc","content":{"id":"CVE-2025-21673","role":"CISA Coordinator","options":[{"Exploitation":"none"},{"Automatable":"no"},{"Technical Impact":"partial"}],"version":"2.0.3","timestamp":"2025-10-01T19:52:08.291891Z"}}}],"problemTypes":[{"descriptions":[{"lang":"en","type":"CWE","cweId":"CWE-415","description":"CWE-415 Double Free"}]}],"title":"CISA ADP Vulnrichment","providerMetadata":{"orgId":"134c704f-9b21-4f2e-91b3-4a467353bcc0","shortName":"CISA-ADP","dateUpdated":"2025-10-01T19:57:12.012Z"}}]}}