Executive brief
A vulnerability in the Linux kernel's networking subsystem could allow a local user to trigger a system warning or instability. The issue occurs when the system attempts to resize a specific internal table used for tracking network connections. While the impact is primarily limited to system reliability, it could be used to disrupt normal operations on affected servers.
Technical details
A vulnerability in the netfilter conntrack component of the Linux kernel arises from improper bounds checking when resizing the connection tracking hashtable. Specifically, the code used UINT_MAX instead of INT_MAX as the maximum size, which can trigger a WARN_ON_ONCE in __kvmalloc_node_noprof() because the __GFP_NOWARN flag is unset for oversized allocations. This issue is reachable only from the initial network namespace (init_netns). An attacker with local access could potentially exploit this to cause kernel warnings or denial-of-service conditions. Patches have been released across multiple stable kernel branches to clamp the maximum size to INT_MAX.
Affected products
- Linux Linux Kernel 4.7.1 to 5.10.233, 5.11 to 5.15.176, 5.16 to 6.1.124, 6.2 to 6.6.71, 6.7 to 6.12.9, 6.13-rc1 to 6.13-rc6
Timeline
- 2025-01-08: patched: Initial patch authored by Pablo Neira Ayuso
- 2025-01-19: disclosed: CVE published
References
- https://git.kernel.org/stable/c/5552b4fd44be3393b930434a7845d8d95a2a3c33
- https://git.kernel.org/stable/c/a965f7f0ea3ae61b9165bed619d5d6da02c75f80
- https://git.kernel.org/stable/c/b1b2353d768f1b80cd7fe045a70adee576b9b338
- https://git.kernel.org/stable/c/b541ba7d1f5a5b7b3e2e22dc9e40e18a7d6dbc13
- https://git.kernel.org/stable/c/d5807dd1328bbc86e059c5de80d1bbee9d58ca3d
- https://git.kernel.org/stable/c/f559357d035877b9d0dcd273e0ff83e18e1d46aa
- https://lists.debian.org/debian-lts-announce/2025/03/msg00001.html