Junglewise Threat Intelligence

CVE-2025-38639: Linux Kernel out-of-bounds read in Netfilter xt_nfacct

CVE-2025-38639 · Severity: high · CVSS 7.1 · Published 2025-08-22

Technologies: Linux Kernel. Vendors: Linux.

Executive brief

A vulnerability was identified in the Linux kernel's networking subsystem (Netfilter) that could allow a local user to cause a system crash or potentially access sensitive information from the computer's memory. The issue occurs when the system attempts to log an error message related to network accounting but fails to properly handle the data, leading to an out-of-bounds memory read. This could impact the stability of the server or lead to unauthorized data exposure.

Technical details

A slab-out-of-bounds read vulnerability exists in net/netfilter/xt_nfacct.c within the nfacct_mt_checkentry function. The root cause is that the code assumes the accounting object name (info->name) is null-terminated when passing it to pr_info_ratelimited for error logging. A local attacker can provide a non-null-terminated string, causing vsnprintf to read past the intended buffer boundary. This can result in a kernel panic (DoS) or the leakage of sensitive kernel memory contents. The issue has been addressed in multiple stable kernel branches by using a precision specifier (%.*s) in the printk format string to limit the read to NFACCT_NAME_MAX.

Affected products

  • Linux Linux Kernel 3.3 to 6.10.x

Timeline

  • 2025-07-18: patched: Initial patch authored by Florian Westphal
  • 2025-08-22: disclosed: CVE-2025-38639 published

References

Related threats