Home

Description

In the Linux kernel, the following vulnerability has been resolved: netfilter: ctnetlink: remove refcounting in expectation dumpers Same pattern as previous patch: do not keep the expectation object alive via refcount, only store a cookie value and then use that as the skip hint for dump resumption. AFAICS this has the same issue as the one resolved in the conntrack dumper, when we do if (!refcount_inc_not_zero(&exp->use)) to increment the refcount, there is a chance that exp == last, which causes a double-increment of the refcount and subsequent memory leak.

PUBLISHED Reserved 2025-04-16 | Published 2025-09-11 | Updated 2026-05-11 | Assigner Linux

Product status

Default status
unaffected

cf6994c2b9812a9f02b99e89df411ffc5db9c779 (git) before b05500444b8eb97644efdd180839a04a706be97c
affected

cf6994c2b9812a9f02b99e89df411ffc5db9c779 (git) before bada48ad5b0590e318d0f79636ff62a2ef9f4955
affected

cf6994c2b9812a9f02b99e89df411ffc5db9c779 (git) before 64b7684042246e3238464c66894e30ba30c7e851
affected

cf6994c2b9812a9f02b99e89df411ffc5db9c779 (git) before 9e5021a906532ca16e2aac69c0607711e1c70b1f
affected

cf6994c2b9812a9f02b99e89df411ffc5db9c779 (git) before 078d33c95bf534d37aa04269d1ae6158e20082d5
affected

cf6994c2b9812a9f02b99e89df411ffc5db9c779 (git) before a4d634ded4d3d400f115d84f654f316f249531c9
affected

cf6994c2b9812a9f02b99e89df411ffc5db9c779 (git) before 1492e3dcb2be3aa46d1963da96aa9593e4e4db5a
affected

Default status
affected

2.6.23
affected

Any version before 2.6.23
unaffected

5.10.253 (semver)
unaffected

5.15.203 (semver)
unaffected

6.1.167 (semver)
unaffected

6.6.130 (semver)
unaffected

6.12.78 (semver)
unaffected

6.16.2 (semver)
unaffected

6.17 (original_commit_for_fix)
unaffected

References

git.kernel.org/...c/b05500444b8eb97644efdd180839a04a706be97c

git.kernel.org/...c/bada48ad5b0590e318d0f79636ff62a2ef9f4955

git.kernel.org/...c/64b7684042246e3238464c66894e30ba30c7e851

git.kernel.org/...c/9e5021a906532ca16e2aac69c0607711e1c70b1f

git.kernel.org/...c/078d33c95bf534d37aa04269d1ae6158e20082d5

git.kernel.org/...c/a4d634ded4d3d400f115d84f654f316f249531c9

git.kernel.org/...c/1492e3dcb2be3aa46d1963da96aa9593e4e4db5a

cve.org (CVE-2025-39764)

nvd.nist.gov (CVE-2025-39764)

Download JSON