Junglewise Threat Intelligence

CVE-2025-38732: Linux Kernel netfilter reference count leak in nf_reject

CVE-2025-38732 · Severity: medium · CVSS 5.5 · Published 2025-09-05

Technologies: Siemens SIMATIC CN 4100, Siemens SIMATIC S7-1500 CPU 1518-4 PN/DP MFP, Linux Kernel. Vendors: Siemens, Linux.

Executive brief

A vulnerability in the Linux kernel's networking subsystem could allow a local user to cause a system crash or instability. The issue occurs when the system processes specific types of internal network traffic (loopback packets) that are rejected by firewall rules. This can lead to a resource leak that eventually exhausts system memory or triggers internal errors, impacting the availability of the device.

Technical details

A vulnerability in the netfilter 'nf_reject' module causes a destination reference count (dst refcount) leak when handling loopback packets. In the PRE_ROUTING and INGRESS stages, loopback packets already have a dst_entry attached; however, the code previously attempted to re-fill the destination entry without checking for an existing one, leading to a leak. An attacker with local access could potentially trigger this leak repeatedly to cause a denial of service (DoS) via resource exhaustion. The fix modifies nf_reject_ipv4.c and nf_reject_ipv6.c to check if a route is already attached (skb_dst) before attempting to fill it.

Affected products

  • Linux Linux Kernel All versions prior to the 2025-08-28 patches
  • Siemens SIMATIC CN 4100 < V5.0
  • Siemens SIMATIC S7-1500 CPU 1518-4 PN/DP MFP >= V3.1.6

Timeline

  • 2025-08-28: patched: Patches committed to Linux stable trees
  • 2025-09-05: disclosed: CVE published

References

Related threats