CVE-2025-38321 (GCVE-0-2025-38321)
Vulnerability from cvelistv5
Published
2025-07-10 08:14
Modified
2026-08-05 12:01
Summary
In the Linux kernel, the following vulnerability has been resolved: smb: Log an error when close_all_cached_dirs fails Under low-memory conditions, close_all_cached_dirs() can't move the dentries to a separate list to dput() them once the locks are dropped. This will result in a "Dentry still in use" error, so add an error message that makes it clear this is what happened: [ 495.281119] CIFS: VFS: \\otters.example.com\share Out of memory while dropping dentries [ 495.281595] ------------[ cut here ]------------ [ 495.281887] BUG: Dentry ffff888115531138{i=78,n=/} still in use (2) [unmount of cifs cifs] [ 495.282391] WARNING: CPU: 1 PID: 2329 at fs/dcache.c:1536 umount_check+0xc8/0xf0 Also, bail out of looping through all tcons as soon as a single allocation fails, since we're already in trouble, and kmalloc() attempts for subseqeuent tcons are likely to fail just like the first one did.
Impacted products
Vendor Product Version
Linux Linux Version: 73934e535cffbda1490fa97d82690a0f9aa73e94
Version: 548812afd96982a76a93ba76c0582ea670c40d9e
Version: 3fa640d035e5ae526769615c35cb9ed4be6e3662
Version: 3fa640d035e5ae526769615c35cb9ed4be6e3662
Version: ff4528bbc82d0d90073751f7b49e7b9e9c7e5638
Version: 6.6.64   
Version: 6.12.2   
Version: 6.11.11   
Create a notification for this product.
Show details on NVD website


{
  "containers": {
    "cna": {
      "affected": [
        {
          "defaultStatus": "unaffected",
          "product": "Linux",
          "programFiles": [
            "fs/smb/client/cached_dir.c"
          ],
          "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
          "vendor": "Linux",
          "versions": [
            {
              "lessThan": "b8ced2b9a23a1a2c1e0ed8d0d02512e51bdf38da",
              "status": "affected",
              "version": "73934e535cffbda1490fa97d82690a0f9aa73e94",
              "versionType": "git"
            },
            {
              "lessThan": "43f26094d6702e494e800532c3f1606e7a68eb30",
              "status": "affected",
              "version": "548812afd96982a76a93ba76c0582ea670c40d9e",
              "versionType": "git"
            },
            {
              "lessThan": "4479db143390bdcadc1561292aab579cdfa9f6c6",
              "status": "affected",
              "version": "3fa640d035e5ae526769615c35cb9ed4be6e3662",
              "versionType": "git"
            },
            {
              "lessThan": "a2182743a8b4969481f64aec4908ff162e8a206c",
              "status": "affected",
              "version": "3fa640d035e5ae526769615c35cb9ed4be6e3662",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "ff4528bbc82d0d90073751f7b49e7b9e9c7e5638",
              "versionType": "git"
            },
            {
              "lessThan": "6.6.95",
              "status": "affected",
              "version": "6.6.64",
              "versionType": "semver"
            },
            {
              "lessThan": "6.12.35",
              "status": "affected",
              "version": "6.12.2",
              "versionType": "semver"
            },
            {
              "lessThan": "6.12",
              "status": "affected",
              "version": "6.11.11",
              "versionType": "semver"
            }
          ]
        },
        {
          "defaultStatus": "affected",
          "product": "Linux",
          "programFiles": [
            "fs/smb/client/cached_dir.c"
          ],
          "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
          "vendor": "Linux",
          "versions": [
            {
              "status": "affected",
              "version": "6.13"
            },
            {
              "lessThan": "6.13",
              "status": "unaffected",
              "version": "0",
              "versionType": "semver"
            },
            {
              "lessThanOrEqual": "6.6.*",
              "status": "unaffected",
              "version": "6.6.95",
              "versionType": "semver"
            },
            {
              "lessThanOrEqual": "6.12.*",
              "status": "unaffected",
              "version": "6.12.35",
              "versionType": "semver"
            },
            {
              "lessThanOrEqual": "6.15.*",
              "status": "unaffected",
              "version": "6.15.4",
              "versionType": "semver"
            },
            {
              "lessThanOrEqual": "*",
              "status": "unaffected",
              "version": "6.16",
              "versionType": "original_commit_for_fix"
            }
          ]
        }
      ],
      "cpeApplicability": [
        {
          "nodes": [
            {
              "cpeMatch": [
                {
                  "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                  "versionEndExcluding": "6.6.95",
                  "versionStartIncluding": "6.6.64",
                  "vulnerable": true
                },
                {
                  "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                  "versionEndExcluding": "6.12.35",
                  "versionStartIncluding": "6.12.2",
                  "vulnerable": true
                },
                {
                  "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                  "versionEndExcluding": "6.15.4",
                  "versionStartIncluding": "6.13",
                  "vulnerable": true
                },
                {
                  "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                  "versionEndExcluding": "6.16",
                  "versionStartIncluding": "6.13",
                  "vulnerable": true
                },
                {
                  "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                  "versionStartIncluding": "6.11.11",
                  "vulnerable": true
                }
              ],
              "negate": false,
              "operator": "OR"
            }
          ]
        }
      ],
      "descriptions": [
        {
          "lang": "en",
          "value": "In the Linux kernel, the following vulnerability has been resolved:\n\nsmb: Log an error when close_all_cached_dirs fails\n\nUnder low-memory conditions, close_all_cached_dirs() can\u0027t move the\ndentries to a separate list to dput() them once the locks are dropped.\nThis will result in a \"Dentry still in use\" error, so add an error\nmessage that makes it clear this is what happened:\n\n[  495.281119] CIFS: VFS: \\\\otters.example.com\\share Out of memory while dropping dentries\n[  495.281595] ------------[ cut here ]------------\n[  495.281887] BUG: Dentry ffff888115531138{i=78,n=/}  still in use (2) [unmount of cifs cifs]\n[  495.282391] WARNING: CPU: 1 PID: 2329 at fs/dcache.c:1536 umount_check+0xc8/0xf0\n\nAlso, bail out of looping through all tcons as soon as a single\nallocation fails, since we\u0027re already in trouble, and kmalloc() attempts\nfor subseqeuent tcons are likely to fail just like the first one did."
        }
      ],
      "metrics": [
        {
          "cvssV3_1": {
            "baseScore": 7.8,
            "baseSeverity": "HIGH",
            "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
            "version": "3.1"
          },
          "scenarios": [
            {
              "lang": "en",
              "value": "AV:L - The vulnerable code runs only in `cifs_kill_sb()` on the local unmount path, and the triggering condition is a local GFP_ATOMIC allocation failure under memory pressure; a remote SMB server can influence how many cached dirs exist but cannot drive the unmount or the OOM.\nAC:L - Memory pressure is directly attacker-inducible and GFP_ATOMIC allocations fail readily under it, and the mount/unmount cycle can be repeated indefinitely, with up to `max_cached_dirs` allocations per tcon per unmount (multiplied further by `multiuser` mounts) giving many independent chances to hit the failure.\nPR:L - A basic unprivileged local account suffices to create the memory pressure, and the unmount is reachable to the same user through the standard `user`/`users` fstab option for SMB shares, setuid `mount.cifs`, or an autofs/systemd idle-expiry unmount; no root or CAP_SYS_ADMIN in the init namespace is required.\nUI:N - On user-mountable shares the attacker performs the mount, the memory exhaustion, and the unmount entirely from their own process, and on automounted shares the expiry unmount happens on a timer with no victim action at all.\nS:U - The leaked dentries, poisoned inodes, and freed superblock are all kernel objects within the same security authority; no VM, IOMMU, or sandbox boundary is crossed.\nC:H - When the tcon is shared with a surviving superblock, the undropped `cfid-\u003edentry` outlives `destroy_super()`, so the later `dput()` reads `dentry-\u003ed_sb` fields (`s_dentry_lru`, `s_d_op`, `s_type`) out of a freed kmalloc-2k object the attacker can reoccupy, giving a use-after-free read primitive over sprayed heap contents.\nI:H - The same dangling `dput()` performs list operations on the freed superblock\u0027s `s_dentry_lru`, writing into attacker-groomed heap memory, and the VFS additionally overwrites `i_op`/`i_sb`/`i_mapping` of the still-referenced inodes \u2014 a use-after-free write primitive usable for control-flow corruption.\nA:H - The failure deterministically produces `WARN(1, \"BUG: Dentry ... still in use\")` in `umount_check()` (a panic under `panic_on_warn`), then `CHECK_DATA_CORRUPTION()` on busy inodes which is an outright `BUG()` with `CONFIG_BUG_ON_DATA_CORRUPTION=y`, and otherwise poisons the inodes so the subsequent `iput_final()` oopses on `VFS_PTR_POISON`."
            }
          ]
        }
      ],
      "providerMetadata": {
        "dateUpdated": "2026-08-05T12:01:08.577Z",
        "orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
        "shortName": "Linux"
      },
      "references": [
        {
          "url": "https://git.kernel.org/stable/c/b8ced2b9a23a1a2c1e0ed8d0d02512e51bdf38da"
        },
        {
          "url": "https://git.kernel.org/stable/c/43f26094d6702e494e800532c3f1606e7a68eb30"
        },
        {
          "url": "https://git.kernel.org/stable/c/4479db143390bdcadc1561292aab579cdfa9f6c6"
        },
        {
          "url": "https://git.kernel.org/stable/c/a2182743a8b4969481f64aec4908ff162e8a206c"
        }
      ],
      "title": "smb: Log an error when close_all_cached_dirs fails",
      "x_generator": {
        "engine": "bippy-1.2.0"
      }
    }
  },
  "cveMetadata": {
    "assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
    "assignerShortName": "Linux",
    "cveId": "CVE-2025-38321",
    "datePublished": "2025-07-10T08:14:57.046Z",
    "dateReserved": "2025-04-16T04:51:24.004Z",
    "dateUpdated": "2026-08-05T12:01:08.577Z",
    "state": "PUBLISHED"
  },
  "dataType": "CVE_RECORD",
  "dataVersion": "5.2"
}


Log in or create an account to share your comment.




Tags
Taxonomy of the tags.


Loading…

Loading…

Loading…

Sightings

Author Source Type Date

Nomenclature

  • Seen: The vulnerability was mentioned, discussed, or seen somewhere by the user.
  • Confirmed: The vulnerability is confirmed from an analyst perspective.
  • Published Proof of Concept: A public proof of concept is available for this vulnerability.
  • Exploited: This vulnerability was exploited and seen by the user reporting the sighting.
  • Patched: This vulnerability was successfully patched by the user reporting the sighting.
  • Not exploited: This vulnerability was not exploited or seen by the user reporting the sighting.
  • Not confirmed: The user expresses doubt about the veracity of the vulnerability.
  • Not patched: This vulnerability was not successfully patched by the user reporting the sighting.


Loading…

Loading…