Junglewise Threat Intelligence

CVE-2025-40206: Linux Kernel infinite recursion in netfilter nft_objref

CVE-2025-40206 · Severity: high · CVSS 7.8 · Published 2025-11-12

Technologies: Linux Kernel. Vendors: Linux.

Executive brief

A vulnerability in the Linux kernel's networking subsystem (Netfilter) can cause a complete system crash. By incorrectly configuring certain firewall rules (specifically referencing a synproxy object in the OUTPUT hook), a local user can trigger an infinite loop that exhausts system resources and crashes the operating system. This impacts the availability of the server and could potentially be used as part of a larger attack to disrupt operations.

Technical details

A vulnerability exists in the nft_objref component of the Linux kernel's Netfilter subsystem. The issue arises when a synproxy stateful object is referenced from the OUTPUT hook, which leads to infinite recursive calls (e.g., synproxy_send_tcp_ipv6 calling itself through the netfilter hooks). This recursion eventually hits the task stack guard page, resulting in a kernel panic. The fix implements validation functions for objref and objrefmap expressions to ensure that NFT_OBJECT_SYNPROXY is only used in supported hooks (LOCAL_IN and FORWARD). Patches have been released for multiple stable kernel branches including 6.6.y, 6.12.y, and 6.17.y.

Affected products

  • Linux Linux Kernel 5.4 to 6.6.113, 6.12.54, 6.17.4

Timeline

  • 2025-10-08: patched: Initial fix authored by Fernando Fernandez Mancera
  • 2025-11-12: disclosed: CVE-2025-40206 published

References

Related threats