Use-After-Free Vulnerability in Linux Kernel's ksmbd Component
CVE-2025-68263
What is CVE-2025-68263?
A use-after-free vulnerability was identified in the ksmbd component of the Linux kernel, specifically involving the ipc_msg_send_request function. The issue arises when ipc_msg_send_request interacts with a generic netlink reply while using an ipc_msg_table_entry. Under conditions of high concurrency, a race condition can occur, allowing handle_response to modify an entry's response after it has already been freed by ipc_msg_send_request. This flaw could lead to a slab-use-after-free situation, as reported by KASAN. Important measures have been implemented to secure this interaction by ensuring that the ipc_msg_table_lock is held during validation and freeing of the response, thereby closing the race condition and restoring consistency to the access of entry->response.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
Linux 0626e6641f6b467447c81dd7678a69c66f7746cf
Linux 0626e6641f6b467447c81dd7678a69c66f7746cf < 708a620b471a14466f1f52c90bf3f65ebdb31460
Linux 0626e6641f6b467447c81dd7678a69c66f7746cf < 5ac763713a1ef8f9a8bda1dbd81f0318d67baa4e