Executive brief
A vulnerability was identified in the Linux kernel's networking component that could lead to a system hang or resource exhaustion. The issue occurs when the system handles specific types of network traffic, causing internal references to network devices to be leaked and never released. In practice, this prevents network administrators from successfully shutting down or reconfiguring network interfaces, potentially leading to a denial of service or requiring a full system reboot to recover.
Technical details
A race condition exists in net/ipv4/route.c between fnhe_remove_oldest() and rt_bind_exception(). When the SIT driver (IPv6 over IPv4 tunneling) triggers the reclamation of oldest Forwarding Next Hop Exception (FNHE) entries, a concurrent path in __mkroute_output() can fetch an entry that is marked for deletion but not yet freed by RCU. If rt_bind_exception() binds this stale entry to a new destination (dst) using dst_hold(), the reference count is leaked when the entry is eventually freed via kfree_rcu(). This results in 'unregister_netdevice' waiting indefinitely for the device usage count to reach zero. The fix involves clearing the fnhe_daddr field before flushing routes to prevent rebinding during the RCU grace period.
Affected products
- Linux Linux Kernel 6.13, 6.12.2, 6.11.11, 6.6.64, 6.1.120, 5.15.174, 5.10.231, 5.4.287, 4.19.325
Timeline
- 2025-11-24: patched: Patch committed to stable trees
- 2025-12-16: disclosed: CVE-2025-68241 published
References
- https://git.kernel.org/stable/c/041ab9ca6e80d8f792bb69df28ebf1ef39c06af8
- https://git.kernel.org/stable/c/0fd16ed6dc331636fb2a874c42d2f7d3156f7ff0
- https://git.kernel.org/stable/c/298f1e0694ab4edb6092d66efed93c4554e6ced1
- https://git.kernel.org/stable/c/4b7210da22429765d19460d38c30eeca72656282
- https://git.kernel.org/stable/c/69d35c12168f9c59b159ae566f77dfad9f96d7ca
- https://git.kernel.org/stable/c/ac1499fcd40fe06479e9b933347b837ccabc2a40
- https://git.kernel.org/stable/c/b84f083f50ecc736a95091691339a1b363962f0e