Junglewise Threat Intelligence

CVE-2025-38721: Linux Kernel reference count leak in netfilter ctnetlink

CVE-2025-38721 · Severity: medium · CVSS 5.5 · Published 2025-09-04

Technologies: Siemens SIMATIC CN 4100, Siemens SIMATIC S7-1500 CPU 1518-4 PN/DP MFP, Linux Kernel. Vendors: Siemens, Linux.

Executive brief

A vulnerability in the Linux kernel's networking subsystem can cause a system hang or prevent certain network modules from being unloaded. This occurs due to a technical error in how the system tracks internal network connections during specific diagnostic tasks. While difficult to trigger, an exploit could lead to a denial-of-service condition, impacting the availability of the affected system.

Technical details

A reference count leak exists in the ctnetlink_dump_table() function within the netfilter subsystem of the Linux kernel. The vulnerability is triggered during a table dump when a specific condition (ct == last) causes a second reference increment that is never decremented. This prevents conntrack objects from being released and keeps the cnet->count from reaching zero, which subsequently blocks network namespace (netns) dismantling or the removal of the conntrack module (rmmod). An attacker with local access could potentially trigger this to cause a kernel worker to spin indefinitely, leading to a denial-of-service. The fix replaces the problematic reference counting with a cookie-based 'skip hint' strategy.

Affected products

  • Linux Linux Kernel Fixed in versions 19b909a, 30cf811, 41462f4, 586892e, 962518c, a2cb4df, a62d6aa, de788b2, e14f72a
  • Siemens SIMATIC CN 4100 < V5.0
  • Siemens SIMATIC S7-1500 CPU 1518-4 PN/DP MFP V3.1.5

Timeline

  • 2025-08-01: patched: Initial patch authored by Florian Westphal
  • 2025-09-04: advisory: CVE-2025-38721 published

References

Related threats