CVE-2025-40271Disclosure

LOWCVSS 7.8 · HIGH

Exploit discussion active in current signal (1 latest mentions)

Immediate actions

  • Patch affected systems immediately
  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft

Recommended action window: High priority (within 72h)

NVD description

In the Linux kernel, the following vulnerability has been resolved: fs/proc: fix uaf in proc_readdir_de() Pde is erased from subdir rbtree through rb_erase(), but not set the node to EMPTY, which may result in uaf access. We should use RB_CLEAR_NODE() set the erased node to EMPTY, then pde_subdir_next() will return NULL to avoid uaf access. We found an uaf issue while using stress-ng testing, need to run testcase getdent and tun in the same time. The steps of the issue is as follows: 1) use getdent to traverse dir /proc/pid/net/dev_snmp6/, and current pde is tun3; 2) in the [time windows] unregister netdevice tun3 and tun2, and erase them from rbtree. erase tun3 first, and then erase tun2. the pde(tun2) will be released to slab; 3) continue to getdent process, then pde_subdir_next() will return pde(tun2) which is released, it will case uaf access. CPU 0 | CPU 1 ------------------------------------------------------------------------- traverse dir /proc/pid/net/dev_snmp6/ | unregister_netdevice(tun->dev) //tun3 tun2 sys_getdents64() | iterate_dir() | proc_readdir() | proc_readdir_de() | snmp6_unregister_dev() pde_get(de); | proc_remove() read_unlock(&proc_subdir_lock); | remove_proc_subtree() | write_lock(&proc_subdir_lock); [time window] | rb_erase(&root->subdir_node, &parent->subdir); | write_unlock(&proc_subdir_lock); read_lock(&proc_subdir_lock); | next = pde_subdir_next(de); | pde_put(de); | de = next; //UAF | rbtree of dev_snmp6 | pde(tun3) / \ NULL pde(tun2)

2.0/ 10 priority

Sources & remediation

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

AVAILABLE

Momentum

STABLE

Threat summary

  • Public PoC is present in monitored signal
  • Patch or workaround signal is available
  • 2 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • PoC mentioned or linked in 1 signal
  • Patch or workaround mentioned in 2 signals
  • Technical details provided in 2 signals
  • Disclosure: 2 classified signals
  • Peaked 1d ago at 1 mentions (2026-05-04); latest day: 1
  • 2 total mentions across 2 days

Deep dive

Activity timeline2 mentions / 2d
00111Mentions · 2026-05-04: 1Mentions · 2026-05-06: 1PoC Mentioned / Linked · 2026-05-06: 1Patch / Workaround · 2026-05-04: 1Patch / Workaround · 2026-05-06: 1Technical Details · 2026-05-04: 1Technical Details · 2026-05-06: 105-0405-06
Signal classification1 categories
Disclosure
2100.0%
Referenced assets1 URL
Full discourse2 posts
  • DFIR Radar@DFIR_Radar
    Disclosure

    CVE-2025-40271 exploits Linux kernel proc_readdir_de() use-after-free in kernels ~3.14+ through 6.18-rc5. Race condition in /proc filesystem allows local privilege escalation via rb-tree traversal of freed proc entries. Technical details: • remove_proc_entry() calls rb_erase() without RB_CLEAR_NODE(), leaving stale rb-tree links • Concurrent getdents64() on /proc/self/net/dev_snmp6/ can traverse freed proc_dir_entry structs • UAF triggered by racing directory reads against network device removal (veth deletion) • Freed 192-byte proc_dir_entry objects sprayed with msg_msg via msgsnd() for heap manipulation • Kernel heap pointer leaked through d_ino field enables KASLR bypass Attack methodology: • Creates user namespace for CAP_NET_ADMIN capability • Populates /proc/self/net/dev_snmp6/ with veth pairs to create target proc entries • Races getdents64() against rapid veth deletion to trigger stale pointer dereference • Sprays kmalloc-192 cache with msg_msg to reclaim freed slots • Detects UAF via anomalous d_ino values (0xffff... kernel addresses) Fixed in stable kernels 5.10.247, 6.1.159, 6.12.73, 6.18-rc6 via commit adding pde_erase() helper. Hunt for unusual d_ino patterns in getdents syscalls and monitor veth creation/deletion patterns. #DFIR_Radar

    Post summary

    The post discloses a detailed Linux kernel use‑after‑free vulnerability (CVE‑2025‑40271), outlines its exploitation method, and references patched kernel versions and mitigation tips.

    100741.5K
    1.7K followersView on X
  • Red Secure Tech Ltd.@redsecuretech
    Disclosure

    A Linux kernel proc readdir use after free (CVE-2025-40271) allows local privilege escalation. Fixed in 5.10.247, 6.1.159, and 6.18-rc6. https://www.redsecuretech.co.uk/blog/post/linux-kernel-proc-readdir-use-after-free-leads-to-root/1160 #CVE #LinuxKernel #UseAfterFree #LocalPrivilegeEscalation #procfs #getdents64 #KernelExploit #InfoSec #LinuxSecurity https://t.co/GxQKSRtnMb

    Post summary

    The Linux kernel proc readdir use‑after‑free vulnerability (CVE‑2025‑40271) allowing local privilege escalation has been disclosed and addressed in recent kernel releases, with additional details available via the provided blog link.

    010101.2K
    48 followersView on X

Explore more