Double free in Linux kernel - CVE-2025-21955
Published: April 2, 2025 / Updated: May 11, 2025
Vulnerability details
The vulnerability allows a local user to perform a denial of service (DoS) attack.
The vulnerability exists due to a double free error within the handle_ksmbd_work() and queue_ksmbd_work() functions in fs/smb/server/server.c, within the __smb2_oplock_break_noti(), smb2_oplock_break_noti(), __smb2_lease_break_noti() and smb2_lease_break_noti() functions in fs/smb/server/oplock.c, within the ksmbd_conn_init_server_callbacks() function in fs/smb/server/connection.c. A local user can perform a denial of service (DoS) attack.
Affected software
Ubuntu
linux (Ubuntu package)
linux-hwe-6.8 (Ubuntu package)
linux-azure-nvidia (Ubuntu package)
linux-azure (Ubuntu package)
linux-ibm (Ubuntu package)
linux-oracle (Ubuntu package)
linux-oracle-6.8 (Ubuntu package)
linux-aws-6.8 (Ubuntu package)
linux-nvidia (Ubuntu package)
linux-raspi (Ubuntu package)
linux-raspi-realtime (Ubuntu package)
linux-realtime (Ubuntu package)
linux-realtime-6.8 (Ubuntu package)
linux-lowlatency (Ubuntu package)
linux-oem-6.11 (Ubuntu package)
How to mitigate CVE-2025-21955
linux (Ubuntu package) - addressed in versions 6.8.0-84.84, 6.8.0-84.84.1, 6.8.0-84.84.1~22.04.1, 6.8.0-1023.25, 6.8.0-1036.40, 6.8.0-1039.41, 6.8.0-1040.42, 6.11.0-28.28, 6.11.0-28.28~24.04.1, 6.11.0-1011.11, 6.11.0-1014.14, 6.11.0-1015.16, 6.11.0-1016.16, 6.11.0-1016.16~24.04.1, 6.11.0-1017.18
linux-hwe-6.8 (Ubuntu package) - addressed in versions 6.8.0-84.84~22.04.1, 6.8.0-85.85~22.04.1
linux-azure-nvidia (Ubuntu package) - update to 6.8.0-1025.27
linux-azure (Ubuntu package) - addressed in versions 6.8.0-1036.42~22.04.1, 6.8.0-1038.44, 6.11.0-1018.18, 6.11.0-1018.18~24.04.1
linux-ibm (Ubuntu package) - addressed in versions 6.8.0-1037.37, 6.8.0-1037.37~22.04.1
linux-oracle (Ubuntu package) - update to 6.8.0-1037.38
linux-oracle-6.8 (Ubuntu package) - update to 6.8.0-1037.38~22.04.1
linux-aws-6.8 (Ubuntu package) - addressed in versions 6.8.0-1039.41~22.04.1, 6.8.0-1040.42~22.04.1
linux-nvidia (Ubuntu package) - addressed in versions 6.8.0-1039.42, 6.8.0-1039.42.1, 6.8.0-1039.42~22.04.1
linux-raspi (Ubuntu package) - update to 6.8.0-1039.43
linux-raspi-realtime (Ubuntu package) - update to 6.8.0-2031.32
linux-realtime (Ubuntu package) - update to 6.8.1-1034.35
linux-realtime-6.8 (Ubuntu package) - update to 6.8.1-1034.35~22.04.1
linux-lowlatency (Ubuntu package) - addressed in versions 6.11.0-1015.16, 6.11.0-1015.16~24.04.2
linux-oem-6.11 (Ubuntu package) - update to 6.11.0-1024.24
External References
- https://git.kernel.org/stable/c/09aeab68033161cb54f194da93e51a11aee6144b
- https://git.kernel.org/stable/c/3aa660c059240e0c795217182cf7df32909dd917
- https://git.kernel.org/stable/c/a4261bbc33fbf99b99c80aa3a2c5097611802980
- https://git.kernel.org/stable/c/f17d1c63a76b0fe8e9c78023a86507a3a6d62cfa
- https://mirrors.edge.kernel.org/pub/linux/kernel/v6.x/ChangeLog-6.13.8
Related Security Bulletins
- Double free in Linux kernel smb server
- Ubuntu update for linux
- Ubuntu update for linux-oem-6.11
- Ubuntu update for linux-lowlatency
- Ubuntu update for linux-azure
- Ubuntu update for linux-nvidia
- Ubuntu update for linux
- Ubuntu update for linux-realtime
- Ubuntu update for linux-aws-6.8
- Ubuntu update for linux-realtime-6.8
- Ubuntu update for linux-ibm
- Ubuntu update for linux-hwe-6.8
- Ubuntu update for linux-raspi
- Ubuntu update for linux-hwe-6.8
- Ubuntu update for linux-raspi-realtime
- Ubuntu update for linux-azure
- Ubuntu update for linux-oracle
- Ubuntu update for linux-azure-nvidia
- Ubuntu update for linux-oracle-6.8