CVE-2025-40271: falha de alta gravidade em Linux
fs/proc: fix uaf in proc_readdir_de()
Publicada em · Atualizada em
41Vexday Risk Score
Sem sinal de exploração. Ela tem prova de conceito pública.
ssvc Attendcvss 7.8epss 0.5%
da publicação à arma149 dias
Publicada no NVD6 de dez.
1ª PoC+149d
probabilidade de exploração
0.5%top 62% das CVEs
exploração observada
nãonenhuma fonte reporta
3 exploit(s) público(s)
In the Linux kernel, the following vulnerability has been resolved:
fs/proc: fix uaf in proc_readdir_de()
Pde is erased from subdir rbtree through rb_erase(), but not set the node
to EMPTY, which may result in uaf access. We should use RB_CLEAR_NODE()
set the erased node to EMPTY, then pde_subdir_next() will return NULL to
avoid uaf access.
We found an uaf issue while using stress-ng testing, need to run testcase
getdent and tun in the same time. The steps of the issue is as follows:
1) use getdent to traverse dir /proc/pid/net/dev_snmp6/, and current
pde is tun3;
2) in the [time windows] unregister netdevice tun3 and tun2, and erase
them from rbtree. erase tun3 first, and then erase tun2. the
pde(tun2) will be released to slab;
3) continue to getdent process, then pde_subdir_next() will return
pde(tun2) which is released, it will case uaf access.
CPU 0 | CPU 1
-------------------------------------------------------------------------
traverse dir /proc/pid/net/dev_snmp6/ | unregister_netdevice(tun->dev) //tun3 tun2
sys_getdents64() |
iterate_dir() |
proc_readdir() |
proc_readdir_de() | snmp6_unregister_dev()
pde_get(de); | proc_remove()
read_unlock(&proc_subdir_lock); | remove_proc_subtree()
| write_lock(&proc_subdir_lock);
[time window] | rb_erase(&root->subdir_node, &parent->subdir);
| write_unlock(&proc_subdir_lock);
read_lock(&proc_subdir_lock); |
next = pde_subdir_next(de); |
pde_put(de); |
de = next; //UAF |
rbtree of dev_snmp6
|
pde(tun3)
/ \
NULL pde(tun2)
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Produtos afetados
Linux · LinuxPoCs públicas encontradas — 3
exploitdbwww.exploit-db.com/exploits/52550não verificadogithubgithub.com/MadExploits/CVE-2025-40271★ 1githubgithub.com/kaleth4/CVE-2025-40271★ 0⚠ Recursos públicos, para você avaliar a exposição de sistemas que controla ou está autorizado a testar. Teste apenas com autorização.
CVEs relacionadas — Linux
No mesmo produto, das mais perigosas para as menos.
CVE-2024-53197HIGHALSA: usb-audio: Fix potential out-of-bound accesses for Extigy and Mbox devicesEPSS 4.1%KEVCVE-2026-31431HIGHcrypto: algif_aead - Revert to operating out-of-placeEPSS 3.4%KEVCVE-2024-53104HIGHmedia: uvcvideo: Skip parsing frames of type UVC_VS_UNDEFINED in uvc_parse_formatEPSS 3.4%KEVCVE-2025-39682CRITICALtls: fix handling of zero-length records on the rx_listEPSS 2.9%KEVCVE-2024-36971HIGHnet: fix __dst_negative_advice() raceEPSS 2.7%KEVCVE-2024-53150HIGHALSA: usb-audio: Fix out of bounds reads when finding clock sourcesEPSS 1.4%KEV
Referências
https://cert-portal.siemens.com/productcert/html/ssa-253495.htmlhttps://git.kernel.org/stable/c/03de7ff197a3d0e17d0d5c58fdac99a63cba8110https://git.kernel.org/stable/c/1d1596d68a6f11d28f677eedf6cf5b17dbfeb491https://git.kernel.org/stable/c/4cba73c4c89219beef7685a47374bf88b1022369https://git.kernel.org/stable/c/623bb26127fb581a741e880e1e1a47d79aecb6f8https://git.kernel.org/stable/c/67272c11f379d9aa5e0f6b16286b9d89b3f76046https://git.kernel.org/stable/c/6f2482745e510ae1dacc9b090194b9c5f918d774https://git.kernel.org/stable/c/895b4c0c79b092d732544011c3cecaf7322c36a1https://git.kernel.org/stable/c/c81d0385500446efe48c305bbb83d47f2ae23a50