Junglewise Threat Intelligence

CVE-2025-21648: Linux Kernel netfilter denial of service in conntrack hashtable resize

CVE-2025-21648 · Severity: medium · CVSS 5.5 · Published 2025-01-19

Technologies: Linux Kernel. Vendors: Linux.

Executive brief

A vulnerability in the Linux kernel's networking subsystem could allow a local user to trigger a system warning or instability. The issue occurs when the system attempts to resize a specific internal table used for tracking network connections. While the impact is primarily limited to system reliability, it could be used to disrupt normal operations on affected servers.

Technical details

A vulnerability in the netfilter conntrack component of the Linux kernel arises from improper bounds checking when resizing the connection tracking hashtable. Specifically, the code used UINT_MAX instead of INT_MAX as the maximum size, which can trigger a WARN_ON_ONCE in __kvmalloc_node_noprof() because the __GFP_NOWARN flag is unset for oversized allocations. This issue is reachable only from the initial network namespace (init_netns). An attacker with local access could potentially exploit this to cause kernel warnings or denial-of-service conditions. Patches have been released across multiple stable kernel branches to clamp the maximum size to INT_MAX.

Affected products

  • Linux Linux Kernel 4.7.1 to 5.10.233, 5.11 to 5.15.176, 5.16 to 6.1.124, 6.2 to 6.6.71, 6.7 to 6.12.9, 6.13-rc1 to 6.13-rc6

Timeline

  • 2025-01-08: patched: Initial patch authored by Pablo Neira Ayuso
  • 2025-01-19: disclosed: CVE published

References

Related threats