Executive brief
A vulnerability in the Linux kernel's networking subsystem could allow a local user to cause a system crash or instability. The issue occurs when the system processes specific types of internal network traffic (loopback packets) that are rejected by firewall rules. This can lead to a resource leak that eventually exhausts system memory or triggers internal errors, impacting the availability of the device.
Technical details
A vulnerability in the netfilter 'nf_reject' module causes a destination reference count (dst refcount) leak when handling loopback packets. In the PRE_ROUTING and INGRESS stages, loopback packets already have a dst_entry attached; however, the code previously attempted to re-fill the destination entry without checking for an existing one, leading to a leak. An attacker with local access could potentially trigger this leak repeatedly to cause a denial of service (DoS) via resource exhaustion. The fix modifies nf_reject_ipv4.c and nf_reject_ipv6.c to check if a route is already attached (skb_dst) before attempting to fill it.
Affected products
- Linux Linux Kernel All versions prior to the 2025-08-28 patches
- Siemens SIMATIC CN 4100 < V5.0
- Siemens SIMATIC S7-1500 CPU 1518-4 PN/DP MFP >= V3.1.6
Timeline
- 2025-08-28: patched: Patches committed to Linux stable trees
- 2025-09-05: disclosed: CVE published
References
- https://git.kernel.org/stable/c/51e8531371f90bee742c63775c9a568e5d6bf3c5
- https://git.kernel.org/stable/c/7b8b503c06274ef3c6c1a107743f1ec0d0a53ef8
- https://git.kernel.org/stable/c/82ef97abf22790182f7d433c74960dfd61b99c33
- https://git.kernel.org/stable/c/91a79b792204313153e1bdbbe5acbfc28903b3a5
- https://git.kernel.org/stable/c/a0a3ace2a57887dac1e7c9a724846040c3e31868
- https://git.kernel.org/stable/c/b32e1590a8d22cf7d7f965e46d5576051acf8e42
- https://git.kernel.org/stable/c/b7a885ba25960c91db237c3f83b4285156789bce