CVE-2025-38527
Last modified
CVE-2025-38527 is a high-severity vulnerability rated 7.8/10 on the CVSS scale. In the Linux kernel, the following vulnerability has been resolved: smb: client: fix use-after-free in cifs_oplock_break A race condition can occur in cifs_oplock_break() leading to a use-after-free of the cinode structure when unmounting: cifs_oplock_break() _cifsFileInfo_put(cfile) cifsFileInfo_put_final() cifs_sb_deactive() [last ref, start releasing sb] kill_sb() kill_anon_super() generic_shutdown_super() evict_inodes() dispose_list() evict() destroy_inode() call_rcu(&inode->i_rcu, i_callback) spin_lock(&cinode->open_file_lock) <- OK [later] i_callback() cifs_free_inode() kmem_cache_free(cinode) spin_unlock(&cinode->open_file_lock) <- UAF cifs_done_oplock_break(cinode) <- UAF The issue occurs when umount has already released its reference to the superblock. When _cifsFileInfo_put() calls cifs_sb_deactive(), this releases the last reference, triggering the immediate cleanup of all inodes under RCU. EPSS estimates a 0.16% chance of exploitation in the next 30 days.
Description
In the Linux kernel, the following vulnerability has been resolved: smb: client: fix use-after-free in cifs_oplock_break A race condition can occur in cifs_oplock_break() leading to a use-after-free of the cinode structure when unmounting: cifs_oplock_break() _cifsFileInfo_put(cfile) cifsFileInfo_put_final() cifs_sb_deactive() [last ref, start releasing sb] kill_sb() kill_anon_super() generic_shutdown_super() evict_inodes() dispose_list() evict() destroy_inode() call_rcu(&inode->i_rcu, i_callback) spin_lock(&cinode->open_file_lock) <- OK [later] i_callback() cifs_free_inode() kmem_cache_free(cinode) spin_unlock(&cinode->open_file_lock) <- UAF cifs_done_oplock_break(cinode) <- UAF The issue occurs when umount has already released its reference to the superblock. When _cifsFileInfo_put() calls cifs_sb_deactive(), this releases the last reference, triggering the immediate cleanup of all inodes under RCU. However, cifs_oplock_break() continues to access the cinode after this point, resulting in use-after-free. Fix this by holding an extra reference to the superblock during the entire oplock break operation. This ensures that the superblock and its inodes remain valid until the oplock break completes.
Metrics
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Weakness Enumeration
Affected Software
| Vendor | Product | Versions | Update |
|---|---|---|---|
| Linux | Linux Kernel | >= 3.16.72, < 3.17 | — |
| Linux | Linux Kernel | >= 4.9.171, < 4.10 | — |
| Linux | Linux Kernel | >= 4.14.114, < 4.15 | — |
| Linux | Linux Kernel | >= 4.19.37, < 4.20 | — |
| Linux | Linux Kernel | >= 5.0.10, < 5.1 | — |
| Linux | Linux Kernel | >= 5.1.1, < 5.15.190 | — |
| Linux | Linux Kernel | >= 5.16, < 6.1.147 | — |
| Linux | Linux Kernel | >= 6.2, < 6.6.100 | — |
| Linux | Linux Kernel | >= 6.7, < 6.12.40 | — |
| Linux | Linux Kernel | >= 6.13, < 6.15.8 | — |
| Linux | Linux Kernel | 5.1 | — |
| Linux | Linux Kernel | 6.16 | Rc1 |
| Debian | Debian Linux | 11.0 | — |
References
- https://lists.debian.org/debian-lts-announce/2025/10/msg00008.htmlMailing List, Third Party Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2025-38527?
How severe is CVE-2025-38527?
How do I fix CVE-2025-38527?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2025
- CVE-2025-38521In the Linux kernel, the following vulnerability has been re…7.1
- CVE-2025-38522In the Linux kernel, the following vulnerability has been re…5.5
- CVE-2025-38523In the Linux kernel, the following vulnerability has been re…5.5
- CVE-2025-38524In the Linux kernel, the following vulnerability has been re…4.7
- CVE-2025-38525In the Linux kernel, the following vulnerability has been re…5.5
- CVE-2025-38526In the Linux kernel, the following vulnerability has been re…5.5
- CVE-2025-38528In the Linux kernel, the following vulnerability has been re…5.5
- CVE-2025-38529In the Linux kernel, the following vulnerability has been re…7.1
- CVE-2025-3853The WPshop 2 – E-Commerce plugin for WordPress is vulnerable…6.5
- CVE-2025-38530In the Linux kernel, the following vulnerability has been re…7.1
- CVE-2025-38531In the Linux kernel, the following vulnerability has been re…5.5
- CVE-2025-38532In the Linux kernel, the following vulnerability has been re…5.5
Are you affected by CVE-2025-38527?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
