Executive brief
A vulnerability in the Linux kernel's networking subsystem could allow a local user to cause a system crash or potentially gain elevated privileges. The issue occurs when the netfilter component, which manages firewall rules, fails to properly handle duplicate network device entries during updates. This can lead to internal kernel errors that disrupt network operations or compromise system stability.
Technical details
A vulnerability exists in the nf_tables component of the Linux kernel netfilter subsystem due to improper validation of device lists during batch updates. When a chain or flowtable update contains duplicate devices in the same transaction batch, the netdev event path only removes the first instance found, leaving the hook for the duplicate device unregistered but still present in internal structures. This inconsistency triggers a kernel WARNING in nf_hook_entry_head during hook unregistration. A local attacker with permissions to modify nftables configurations could exploit this to cause a Denial of Service (DoS) or potentially achieve further kernel-level impact. The fix introduces a check for duplicate devices in the transaction batch, returning EEXIST if duplicates are detected.
Affected products
- Linux Linux Kernel 5.8 to 5.10.247, 5.15.197, 6.1.159, 6.6.117, 6.12.59, 6.16.2
Timeline
- 2025-09-03: advisory: CVE published by NVD
- 2025-11-17: patched: Initial fix authored by Pablo Neira Ayuso
References
- https://git.kernel.org/stable/c/0521e694d5b80899fba8695881a6349f9bc538cb
- https://git.kernel.org/stable/c/3f358a66a04513311668ea4b40f5064e253d8386
- https://git.kernel.org/stable/c/4681960bc0f4f8bcc782cbf2fd205f48ad314dfd
- https://git.kernel.org/stable/c/4ce2a0c3b8497a66cfc25fc7ca3d087258a785d2
- https://git.kernel.org/stable/c/cf23d531a9d496863aa4c5a0e2f71f0a23f3df3c
- https://git.kernel.org/stable/c/cf5fb87fcdaaaafec55dcc0dc5a9e15ead343973
- https://git.kernel.org/stable/c/d7615bde541f16517d6790412da6ec46fa8a4c1f