{
    "dataType": "CVE_RECORD",
    "dataVersion": "5.2",
    "cveMetadata": {
        "cveId": "CVE-2025-38321",
        "assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
        "state": "PUBLISHED",
        "assignerShortName": "Linux",
        "dateReserved": "2025-04-16T04:51:24.004Z",
        "datePublished": "2025-07-10T08:14:57.046Z",
        "dateUpdated": "2026-08-05T12:01:08.577Z"
    },
    "containers": {
        "cna": {
            "providerMetadata": {
                "orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
                "shortName": "Linux",
                "dateUpdated": "2026-08-05T12:01:08.577Z"
            },
            "descriptions": [
                {
                    "lang": "en",
                    "value": "In the Linux kernel, the following vulnerability has been resolved:\n\nsmb: Log an error when close_all_cached_dirs fails\n\nUnder low-memory conditions, close_all_cached_dirs() can't move the\ndentries to a separate list to dput() them once the locks are dropped.\nThis will result in a \"Dentry still in use\" error, so add an error\nmessage that makes it clear this is what happened:\n\n[  495.281119] CIFS: VFS: \\\\otters.example.com\\share Out of memory while dropping dentries\n[  495.281595] ------------[ cut here ]------------\n[  495.281887] BUG: Dentry ffff888115531138{i=78,n=/}  still in use (2) [unmount of cifs cifs]\n[  495.282391] WARNING: CPU: 1 PID: 2329 at fs/dcache.c:1536 umount_check+0xc8/0xf0\n\nAlso, bail out of looping through all tcons as soon as a single\nallocation fails, since we're already in trouble, and kmalloc() attempts\nfor subseqeuent tcons are likely to fail just like the first one did."
                }
            ],
            "metrics": [
                {
                    "cvssV3_1": {
                        "version": "3.1",
                        "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
                        "baseScore": 7.8,
                        "baseSeverity": "HIGH"
                    },
                    "scenarios": [
                        {
                            "lang": "en",
                            "value": "AV:L - The vulnerable code runs only in `cifs_kill_sb()` on the local unmount path, and the triggering condition is a local GFP_ATOMIC allocation failure under memory pressure; a remote SMB server can influence how many cached dirs exist but cannot drive the unmount or the OOM.\nAC:L - Memory pressure is directly attacker-inducible and GFP_ATOMIC allocations fail readily under it, and the mount/unmount cycle can be repeated indefinitely, with up to `max_cached_dirs` allocations per tcon per unmount (multiplied further by `multiuser` mounts) giving many independent chances to hit the failure.\nPR:L - A basic unprivileged local account suffices to create the memory pressure, and the unmount is reachable to the same user through the standard `user`/`users` fstab option for SMB shares, setuid `mount.cifs`, or an autofs/systemd idle-expiry unmount; no root or CAP_SYS_ADMIN in the init namespace is required.\nUI:N - On user-mountable shares the attacker performs the mount, the memory exhaustion, and the unmount entirely from their own process, and on automounted shares the expiry unmount happens on a timer with no victim action at all.\nS:U - The leaked dentries, poisoned inodes, and freed superblock are all kernel objects within the same security authority; no VM, IOMMU, or sandbox boundary is crossed.\nC:H - When the tcon is shared with a surviving superblock, the undropped `cfid->dentry` outlives `destroy_super()`, so the later `dput()` reads `dentry->d_sb` fields (`s_dentry_lru`, `s_d_op`, `s_type`) out of a freed kmalloc-2k object the attacker can reoccupy, giving a use-after-free read primitive over sprayed heap contents.\nI:H - The same dangling `dput()` performs list operations on the freed superblock's `s_dentry_lru`, writing into attacker-groomed heap memory, and the VFS additionally overwrites `i_op`/`i_sb`/`i_mapping` of the still-referenced inodes — a use-after-free write primitive usable for control-flow corruption.\nA:H - The failure deterministically produces `WARN(1, \"BUG: Dentry ... still in use\")` in `umount_check()` (a panic under `panic_on_warn`), then `CHECK_DATA_CORRUPTION()` on busy inodes which is an outright `BUG()` with `CONFIG_BUG_ON_DATA_CORRUPTION=y`, and otherwise poisons the inodes so the subsequent `iput_final()` oopses on `VFS_PTR_POISON`."
                        }
                    ]
                }
            ],
            "affected": [
                {
                    "product": "Linux",
                    "vendor": "Linux",
                    "defaultStatus": "unaffected",
                    "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
                    "programFiles": [
                        "fs/smb/client/cached_dir.c"
                    ],
                    "versions": [
                        {
                            "version": "73934e535cffbda1490fa97d82690a0f9aa73e94",
                            "lessThan": "b8ced2b9a23a1a2c1e0ed8d0d02512e51bdf38da",
                            "status": "affected",
                            "versionType": "git"
                        },
                        {
                            "version": "548812afd96982a76a93ba76c0582ea670c40d9e",
                            "lessThan": "43f26094d6702e494e800532c3f1606e7a68eb30",
                            "status": "affected",
                            "versionType": "git"
                        },
                        {
                            "version": "3fa640d035e5ae526769615c35cb9ed4be6e3662",
                            "lessThan": "4479db143390bdcadc1561292aab579cdfa9f6c6",
                            "status": "affected",
                            "versionType": "git"
                        },
                        {
                            "version": "3fa640d035e5ae526769615c35cb9ed4be6e3662",
                            "lessThan": "a2182743a8b4969481f64aec4908ff162e8a206c",
                            "status": "affected",
                            "versionType": "git"
                        },
                        {
                            "version": "ff4528bbc82d0d90073751f7b49e7b9e9c7e5638",
                            "status": "affected",
                            "versionType": "git"
                        },
                        {
                            "version": "6.6.64",
                            "lessThan": "6.6.95",
                            "status": "affected",
                            "versionType": "semver"
                        },
                        {
                            "version": "6.12.2",
                            "lessThan": "6.12.35",
                            "status": "affected",
                            "versionType": "semver"
                        },
                        {
                            "version": "6.11.11",
                            "lessThan": "6.12",
                            "status": "affected",
                            "versionType": "semver"
                        }
                    ]
                },
                {
                    "product": "Linux",
                    "vendor": "Linux",
                    "defaultStatus": "affected",
                    "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
                    "programFiles": [
                        "fs/smb/client/cached_dir.c"
                    ],
                    "versions": [
                        {
                            "version": "6.13",
                            "status": "affected"
                        },
                        {
                            "version": "0",
                            "lessThan": "6.13",
                            "status": "unaffected",
                            "versionType": "semver"
                        },
                        {
                            "version": "6.6.95",
                            "lessThanOrEqual": "6.6.*",
                            "status": "unaffected",
                            "versionType": "semver"
                        },
                        {
                            "version": "6.12.35",
                            "lessThanOrEqual": "6.12.*",
                            "status": "unaffected",
                            "versionType": "semver"
                        },
                        {
                            "version": "6.15.4",
                            "lessThanOrEqual": "6.15.*",
                            "status": "unaffected",
                            "versionType": "semver"
                        },
                        {
                            "version": "6.16",
                            "lessThanOrEqual": "*",
                            "status": "unaffected",
                            "versionType": "original_commit_for_fix"
                        }
                    ]
                }
            ],
            "cpeApplicability": [
                {
                    "nodes": [
                        {
                            "operator": "OR",
                            "negate": false,
                            "cpeMatch": [
                                {
                                    "vulnerable": true,
                                    "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                                    "versionStartIncluding": "6.6.64",
                                    "versionEndExcluding": "6.6.95"
                                },
                                {
                                    "vulnerable": true,
                                    "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                                    "versionStartIncluding": "6.12.2",
                                    "versionEndExcluding": "6.12.35"
                                },
                                {
                                    "vulnerable": true,
                                    "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                                    "versionStartIncluding": "6.13",
                                    "versionEndExcluding": "6.15.4"
                                },
                                {
                                    "vulnerable": true,
                                    "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                                    "versionStartIncluding": "6.13",
                                    "versionEndExcluding": "6.16"
                                },
                                {
                                    "vulnerable": true,
                                    "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                                    "versionStartIncluding": "6.11.11"
                                }
                            ]
                        }
                    ]
                }
            ],
            "references": [
                {
                    "url": "https://git.kernel.org/stable/c/b8ced2b9a23a1a2c1e0ed8d0d02512e51bdf38da"
                },
                {
                    "url": "https://git.kernel.org/stable/c/43f26094d6702e494e800532c3f1606e7a68eb30"
                },
                {
                    "url": "https://git.kernel.org/stable/c/4479db143390bdcadc1561292aab579cdfa9f6c6"
                },
                {
                    "url": "https://git.kernel.org/stable/c/a2182743a8b4969481f64aec4908ff162e8a206c"
                }
            ],
            "title": "smb: Log an error when close_all_cached_dirs fails",
            "x_generator": {
                "engine": "bippy-1.2.0"
            }
        }
    }
}