In the Linux kernel, the following vulnerability has been resolved: smc: Use __sk_dst_get() and dst_dev_rcu() in in smc_clc_prfx_set(). (CVE-2025-40139)
A use-after-free (UAF) vulnerability in the Linux kernel's smc_clc_prfx_set() function was resolved by changing how socket destination device references are accessed. The flaw involved unsafe use of sk_dst_get(sk)->dev without proper synchronization, which could lead to memory corruption. The fix uses __sk_dst_get() and dst_dev_rcu() under RCU read lock to prevent UAF. This vulnerability affects local attackers with low privileges and can result in high impact on confidentiality, integrity, and availability.
AI Analysis
Technical Summary
CVE-2025-40139 is a vulnerability in the Linux kernel's SMC (Shared Memory Communications) subsystem. The function smc_clc_prfx_set(), called during connect(), accessed sk_dst_get(sk)->dev without proper synchronization, potentially triggering a use-after-free condition. The patch replaces this with __sk_dst_get() and dst_dev_rcu() calls under an RCU read lock, ensuring safe access to the destination device pointer. The vulnerability allows a local attacker with low privileges to cause high impact on system confidentiality, integrity, and availability.
Potential Impact
The vulnerability allows a local attacker with low privileges to exploit a use-after-free condition in the Linux kernel, potentially leading to arbitrary code execution or kernel memory corruption. The CVSS vector indicates high impact on confidentiality, integrity, and availability. No known exploits in the wild have been reported.
Mitigation Recommendations
A fix for this vulnerability has been implemented in the Linux kernel by modifying smc_clc_prfx_set() to use __sk_dst_get() and dst_dev_rcu() under RCU read lock. Users should apply the official kernel updates containing this patch when available. Patch status is not yet confirmed — check the vendor advisory for current remediation guidance.
In the Linux kernel, the following vulnerability has been resolved: smc: Use __sk_dst_get() and dst_dev_rcu() in in smc_clc_prfx_set(). (CVE-2025-40139)
Description
A use-after-free (UAF) vulnerability in the Linux kernel's smc_clc_prfx_set() function was resolved by changing how socket destination device references are accessed. The flaw involved unsafe use of sk_dst_get(sk)->dev without proper synchronization, which could lead to memory corruption. The fix uses __sk_dst_get() and dst_dev_rcu() under RCU read lock to prevent UAF. This vulnerability affects local attackers with low privileges and can result in high impact on confidentiality, integrity, and availability.
CVSS v3.1
Score 7.8high
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
CVE-2025-40139 is a vulnerability in the Linux kernel's SMC (Shared Memory Communications) subsystem. The function smc_clc_prfx_set(), called during connect(), accessed sk_dst_get(sk)->dev without proper synchronization, potentially triggering a use-after-free condition. The patch replaces this with __sk_dst_get() and dst_dev_rcu() calls under an RCU read lock, ensuring safe access to the destination device pointer. The vulnerability allows a local attacker with low privileges to cause high impact on system confidentiality, integrity, and availability.
Potential Impact
The vulnerability allows a local attacker with low privileges to exploit a use-after-free condition in the Linux kernel, potentially leading to arbitrary code execution or kernel memory corruption. The CVSS vector indicates high impact on confidentiality, integrity, and availability. No known exploits in the wild have been reported.
Mitigation Recommendations
A fix for this vulnerability has been implemented in the Linux kernel by modifying smc_clc_prfx_set() to use __sk_dst_get() and dst_dev_rcu() under RCU read lock. Users should apply the official kernel updates containing this patch when available. Patch status is not yet confirmed — check the vendor advisory for current remediation guidance.
Technical Details
- Gcve Source
- db.gcve.eu
- Osv Id
- GHSA-ffj5-vpjf-2hxm
- Osv Schema Version
- 1.4.0
- Aliases
- ["CVE-2025-40139"]
- Database Specific Severity
- HIGH
- Cvss Version
- 3.1
Threat ID: 6a6b72d69c2644c7f847a8ee
Added to database: 07/30/2026, 15:50:46 UTC
Last enriched: 07/30/2026, 16:43:04 UTC
Last updated: 09/10/2026, 19:38:44 UTC
Views: 7
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.