CVE-2025-68366: nbd: defer config unlock in nbd_genl_connect
In the Linux kernel, the following vulnerability has been resolved:
nbd: defer config unlock in nbdgenlconnect
There is one use-after-free warning when running NBDCMDCONNECT and NBDCLEARSOCK:
nbdgenlconnect nbdallocandinitconfig // configrefs=1 nbdstartdevice // configrefs=2 set NBDRTHASCONFIGREF open nbd // configrefs=3 recvwork done // configrefs=2 NBDCLEARSOCK // configrefs=1 close nbd // configrefs=0 refcountinc -> uaf
------------[ cut here ]------------ refcountt: addition on 0; use-after-free. WARNING: CPU: 24 PID: 1014 at lib/refcount.c:25 refcountwarnsaturate+0x12e/0x290 nbdgenlconnect+0x16d0/0x1ab0 genlfamilyrcvmsgdoit+0x1f3/0x310 genlrcvmsg+0x44a/0x790
The issue can be easily reproduced by adding a small delay before refcountinc(&nbd->configrefs) in nbdgenlconnect():
mutexunlock(&nbd->configlock); if (!ret) { setbit(NBDRTHASCONFIGREF, &config->runtimeflags); + printk("before sleep\n"); + mdelay(5 1000); + printk("after sleep\n"); refcountinc(&nbd->configrefs); nbdconnectreply(info, nbd->index); }
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-68366?
CVE-2025-68366 has been classified as a medium severity vulnerability in the Linux kernel.
How do I fix CVE-2025-68366?
To resolve CVE-2025-68366, you should update to the latest version of the Linux kernel that includes the patch for this vulnerability.
What are the potential impacts of CVE-2025-68366?
The potential impacts of CVE-2025-68366 include possible denial of service or system instability due to a use-after-free condition.
Which versions of the Linux kernel are affected by CVE-2025-68366?
CVE-2025-68366 affects various versions of the Linux kernel prior to the patch release addressing the vulnerability.
Is CVE-2025-68366 exploitable?
Yes, CVE-2025-68366 is considered exploitable under certain conditions, which could lead to a denial of service.