
CVE-2025-40271 exploits Linux kernel proc_readdir_de() use-after-free in kernels ~3.14+ through 6.18-rc5. Race condition in /proc filesystem allows local privilege escalation via rb-tree traversal of freed proc entries. Technical details: • remove_proc_entry() calls rb_erase() without RB_CLEAR_NODE(), leaving stale rb-tree links • Concurrent getdents64() on /proc/self/net/dev_snmp6/ can traverse freed proc_dir_entry structs • UAF triggered by racing directory reads against network device removal (veth deletion) • Freed 192-byte proc_dir_entry objects sprayed with msg_msg via msgsnd() for heap manipulation • Kernel heap pointer leaked through d_ino field enables KASLR bypass Attack methodology: • Creates user namespace for CAP_NET_ADMIN capability • Populates /proc/self/net/dev_snmp6/ with veth pairs to create target proc entries • Races getdents64() against rapid veth deletion to trigger stale pointer dereference • Sprays kmalloc-192 cache with msg_msg to reclaim freed slots • Detects UAF via anomalous d_ino values (0xffff... kernel addresses) Fixed in stable kernels 5.10.247, 6.1.159, 6.12.73, 6.18-rc6 via commit adding pde_erase() helper. Hunt for unusual d_ino patterns in getdents syscalls and monitor veth creation/deletion patterns. #DFIR_Radar
Post summary
The post discloses a detailed Linux kernel use‑after‑free vulnerability (CVE‑2025‑40271), outlines its exploitation method, and references patched kernel versions and mitigation tips.

