Junglewise Threat Intelligence

CVE-2025-40183: Linux Kernel memory leak in BPF redirect_neigh helper

CVE-2025-40183 · Severity: high · CVSS 7.5 · Published 2025-11-12

Technologies: Linux Kernel. Vendors: Linux.

Executive brief

A memory leak vulnerability was identified in the Linux kernel's networking component, specifically affecting systems using BPF-based redirection like Cilium egress gateways. This flaw causes the system to gradually consume more memory as network traffic is processed, which can eventually lead to a system crash or service outage. Organizations using Kubernetes with Cilium or similar VXLAN-based networking configurations are most at risk of experiencing operational instability.

Technical details

A memory leak exists in the __bpf_redirect_neigh_v4 and __bpf_redirect_neigh_v6 functions within the Linux kernel's BPF implementation. The root cause is that the bpf_redirect_neigh() helper sets a new destination entry (dst) for a socket buffer (skb) using skb_dst_set() without first releasing the existing metadata_dst object allocated by VXLAN. This results in an ever-increasing consumption of the kmalloc-256 slab. An attacker can trigger this leak by sending network traffic through a system configured with BPF egress gateways and VXLAN tunnels in 'collect md' mode. The vulnerability has been patched in multiple stable kernel branches including 5.10.y, 5.15.y, 6.1.y, 6.6.y, and 6.12.y.

Affected products

  • Linux Linux Kernel 5.10 to 5.10.246, 5.15.195, 6.1.157, 6.6.113, 6.12.54, 6.17.4

Timeline

  • 2025-10-03: patched: Initial patch authored by Daniel Borkmann
  • 2025-11-12: disclosed: CVE-2025-40183 published

References

Related threats