CVE-2025-21673
Linux Kernel vulnerability analysis and mitigation

Overview

CVE-2025-21673 is a double free vulnerability discovered in the Linux kernel's SMB client implementation, specifically affecting the TCP_Server_Info::hostname handling. The vulnerability was disclosed on January 31, 2025, and affects Linux kernel versions from 5.14.19 up to (excluding) 6.12.11 (NVD).

Technical details

The vulnerability occurs when shutting down the server in cifs_put_tcp_session(). During this process, the cifsd thread might be reconnecting to multiple DFS targets before realizing it should exit the loop, leading to a potential double free of server->hostname. The issue stems from improper memory management where the hostname is freed before the cifsd thread completes its operations. The vulnerability has been assigned a CVSS v3.1 base score of 5.5 (Medium) with vector string CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H (NVD).

Impact

The vulnerability can lead to system instability and potential denial of service conditions due to memory corruption. When exploited, it can cause the kernel to crash, resulting in system downtime. The vulnerability affects the availability of the system but does not impact confidentiality or integrity (NVD).

Mitigation and workarounds

The vulnerability has been patched in the Linux kernel. The fix involves ensuring that server->hostname is not freed until the cifsd thread has completed its operations by moving the free operation to clean_demultiplex_info(). System administrators are advised to update to patched kernel versions. Red Hat Enterprise Linux 9 users should apply the available kernel updates, while versions 6, 7, and 8 are not affected (Red Hat).

Additional resources


SourceThis report was generated using AI

Related Linux Kernel vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2025-71142N/AN/A
  • Linux KernelLinux Kernel
  • kernel-zfcpdump-modules-core
NoNoJan 14, 2026
CVE-2025-71137N/AN/A
  • Linux KernelLinux Kernel
  • kernel-64k-debug-devel-matched
NoYesJan 14, 2026
CVE-2025-71135N/AN/A
  • Linux KernelLinux Kernel
  • kernel-doc
NoNoJan 14, 2026
CVE-2025-71134N/AN/A
  • Linux KernelLinux Kernel
  • kernel-abi-stablelists
NoNoJan 14, 2026
CVE-2025-71133N/AN/A
  • Linux KernelLinux Kernel
  • kernel-zfcpdump-modules
NoYesJan 14, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management