Executive brief
A vulnerability in the Linux kernel's networking subsystem can cause a system hang or prevent certain network modules from being unloaded. This occurs due to a technical error in how the system tracks internal network connections during specific diagnostic tasks. While difficult to trigger, an exploit could lead to a denial-of-service condition, impacting the availability of the affected system.
Technical details
A reference count leak exists in the ctnetlink_dump_table() function within the netfilter subsystem of the Linux kernel. The vulnerability is triggered during a table dump when a specific condition (ct == last) causes a second reference increment that is never decremented. This prevents conntrack objects from being released and keeps the cnet->count from reaching zero, which subsequently blocks network namespace (netns) dismantling or the removal of the conntrack module (rmmod). An attacker with local access could potentially trigger this to cause a kernel worker to spin indefinitely, leading to a denial-of-service. The fix replaces the problematic reference counting with a cookie-based 'skip hint' strategy.
Affected products
- Linux Linux Kernel Fixed in versions 19b909a, 30cf811, 41462f4, 586892e, 962518c, a2cb4df, a62d6aa, de788b2, e14f72a
- Siemens SIMATIC CN 4100 < V5.0
- Siemens SIMATIC S7-1500 CPU 1518-4 PN/DP MFP V3.1.5
Timeline
- 2025-08-01: patched: Initial patch authored by Florian Westphal
- 2025-09-04: advisory: CVE-2025-38721 published
References
- https://git.kernel.org/stable/c/19b909a4b1452fb97e477d2f08b97f8d04095619
- https://git.kernel.org/stable/c/30cf811058552b8cd0e98dff677ef3f89d6d34ce
- https://git.kernel.org/stable/c/41462f4cfc583513833f87f9ee55d12da651a7e3
- https://git.kernel.org/stable/c/586892e341fbf698e7cbaca293e1353957db725a
- https://git.kernel.org/stable/c/962518c6ca9f9a13df099cafa429f72f68ad61f0
- https://git.kernel.org/stable/c/a2cb4df7872de069f809de2f076ec8e54d649fe3
- https://git.kernel.org/stable/c/a62d6aa3f31f216b637a4c71b7a8bfc7c57f049b