Executive brief
A vulnerability in the Linux kernel's networking subsystem could allow a local user to cause a memory leak, potentially leading to a system crash or instability. The issue occurs within the Netfilter component, which manages network traffic filtering and connection tracking. By repeatedly triggering specific network status requests, an attacker could exhaust system memory, impacting the availability of the device or server.
Technical details
A vulnerability in the Linux kernel's netfilter/nf_conntrack_netlink.c component arises from improper reference counting in expectation dumpers. When resuming a dump, the code may double-increment the reference count of an expectation object if the current object matches the last one processed (exp == last). This leads to a permanent memory leak because the object's reference count never reaches zero, preventing it from being freed. An attacker with local access can exploit this by repeatedly initiating ctnetlink expectation dumps to exhaust kernel memory. The fix replaces reference counting with a cookie-based (ID) skip hint for dump resumption.
Affected products
- Linux Linux Kernel All versions prior to the 2025-08-01 fix
- Siemens SIMATIC S7-1500 CPU 1518-4 PN/DP MFP V3.1.5, V3.1.6
Timeline
- 2025-08-01: patched: Initial fix authored by Florian Westphal
- 2025-09-11: disclosed: CVE published
References
- https://git.kernel.org/stable/c/078d33c95bf534d37aa04269d1ae6158e20082d5
- https://git.kernel.org/stable/c/1492e3dcb2be3aa46d1963da96aa9593e4e4db5a
- https://git.kernel.org/stable/c/64b7684042246e3238464c66894e30ba30c7e851
- https://git.kernel.org/stable/c/9e5021a906532ca16e2aac69c0607711e1c70b1f
- https://git.kernel.org/stable/c/a4d634ded4d3d400f115d84f654f316f249531c9
- https://git.kernel.org/stable/c/b05500444b8eb97644efdd180839a04a706be97c
- https://git.kernel.org/stable/c/bada48ad5b0590e318d0f79636ff62a2ef9f4955