cbcvebase.
CVE-2025-21959
published 2025-04-01

CVE-2025-21959: In the Linux kernel, the following vulnerability has been resolved: netfilter: nf_conncount: Fully initialize struct nf_conncount_tuple in insert_tree() Since…

PriorityP420medium5.5CVSS 3.1
AVLACLPRLUINSUCNINAH
EPSS
0.40%
32.8th percentile
In the Linux kernel, the following vulnerability has been resolved: netfilter: nf_conncount: Fully initialize struct nf_conncount_tuple in insert_tree() Since commit b36e4523d4d5 ("netfilter: nf_conncount: fix garbage collection confirm race"), `cpu` and `jiffies32` were introduced to the struct nf_conncount_tuple. The commit made nf_conncount_add() initialize `conn->cpu` and `conn->jiffies32` when allocating the struct. In contrast, count_tree() was not changed to initialize them. By commit 34848d5c896e ("netfilter: nf_conncount: Split insert and traversal"), count_tree() was split and the relevant allocation code now resides in insert_tree(). Initialize `conn->cpu` and `conn->jiffies32` in insert_tree(). BUG: KMSAN: uninit-value in find_or_evict net/netfilter/nf_conncount.c:117 [inline] BUG: KMSAN: uninit-value in __nf_conncount_add+0xd9c/0x2850 net/netfilter/nf_conncount.c:143 find_or_evict net/netfilter/nf_conncount.c:117 [inline] __nf_conncount_add+0xd9c/0x2850 net/netfilter/nf_conncount.c:143 count_tree net/netfilter/nf_conncount.c:438 [inline] nf_conncount_count+0x82f/0x1e80 net/netfilter/nf_conncount.c:521 connlimit_mt+0x7f6/0xbd0 net/netfilter/xt_connlimit.c:72 __nft_match_eval net/netfilter/nft_compat.c:403 [inline] nft_match_eval+0x1a5/0x300 net/netfilter/nft_compat.c:433 expr_call_ops_eval net/netfilter/nf_tables_core.c:240 [inline] nft_do_chain+0x426/0x2290 net/netfilter/nf_tables_core.c:288 nft_do_chain_ipv4+0x1a5/0x230 net/netfilter/nft_chain_filter.c:23 nf_hook_entry_hookfn include/linux/netfilter.h:154 [inline] nf_hook_slow+0xf4/0x400 net/netfilter/core.c:626 nf_hook_slow_list+0x24d/0x860 net/netfilter/core.c:663 NF_HOOK_LIST include/linux/netfilter.h:350 [inline] ip_sublist_rcv+0x17b7/0x17f0 net/ipv4/ip_input.c:633 ip_list_rcv+0x9ef/0xa40 net/ipv4/ip_input.c:669 __netif_receive_skb_list_ptype net/core/dev.c:5936 [inline] __netif_receive_skb_list_core+0x15c5/0x1670 net/core/dev.c:5983 __netif_receive_skb_list net/core/dev.c:6035 [inline] netif_

Affected

40 ranges· showing 25
VendorProductVersion rangeFixed in
debianlinux< linux 6.1.133-1 (bookworm)linux 6.1.133-1 (bookworm)
debianlinux-6.1< linux 6.1.133-1 (bookworm)linux 6.1.133-1 (bookworm)
linuxlinux
linuxlinux
linuxlinux>= 4.14.92 < 4.154.15
linuxlinux>= b36e4523d4d56e2595e28f16f6ccf1cd6a9fc452 < f522229c5563b59b4240261e406779bba6754159f522229c5563b59b4240261e406779bba6754159
linuxlinux>= b36e4523d4d56e2595e28f16f6ccf1cd6a9fc452 < 2a154ce766b995494e88d8d117fa82cc6b73dd872a154ce766b995494e88d8d117fa82cc6b73dd87
linuxlinux>= b36e4523d4d56e2595e28f16f6ccf1cd6a9fc452 < e8544a5a97bee3674e7cd6bf0f3a4af517fa9146e8544a5a97bee3674e7cd6bf0f3a4af517fa9146
linuxlinux>= b36e4523d4d56e2595e28f16f6ccf1cd6a9fc452 < a62a25c6ad58fae997f48a0749afeda1c252ae51a62a25c6ad58fae997f48a0749afeda1c252ae51
linuxlinux>= b36e4523d4d56e2595e28f16f6ccf1cd6a9fc452 < fda50302a13701d47fbe01e1739c7a51114144fbfda50302a13701d47fbe01e1739c7a51114144fb
linuxlinux>= b36e4523d4d56e2595e28f16f6ccf1cd6a9fc452 < db1e0c0856821c59a32ea3af79476bf20a6beeb2db1e0c0856821c59a32ea3af79476bf20a6beeb2
linuxlinux>= b36e4523d4d56e2595e28f16f6ccf1cd6a9fc452 < 2db5baaf047a7c8d6ed5e2cc657b7854e155b7fc2db5baaf047a7c8d6ed5e2cc657b7854e155b7fc
linuxlinux>= b36e4523d4d56e2595e28f16f6ccf1cd6a9fc452 < d653bfeb07ebb3499c403404c21ac58a16531607d653bfeb07ebb3499c403404c21ac58a16531607
linuxlinux_kernel
linuxlinux_kernel
linuxlinux_kernel
linuxlinux_kernel
linuxlinux_kernel
linuxlinux_kernel
linuxlinux_kernel>= 0 < 5.10.237-15.10.237-1
linuxlinux_kernel>= 0 < 6.1.133-16.1.133-1
linuxlinux_kernel>= 0 < 6.12.20-16.12.20-1
linuxlinux_kernel>= 0 < 6.12.20-16.12.20-1
linuxlinux_kernel>= 0 < 5.15.0-142.1525.15.0-142.152
linuxlinux_kernel>= 0 < 6.8.0-84.846.8.0-84.84

CVSS provenance

nvdv3.15.5MEDIUMCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
osv8.8HIGH
vendor_ubuntu8.8HIGH
vendor_debian5.5MEDIUM
vendor_msrc5.5MEDIUM
vendor_redhat5.5MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.