cbcvebase.
CVE-2025-38732
published 2025-09-05

CVE-2025-38732: In the Linux kernel, the following vulnerability has been resolved: netfilter: nf_reject: don't leak dst refcount for loopback packets recent patches to add a…

medium5.5CVSS 3.1
AVLACLPRLUINSUCNINAH
In the Linux kernel, the following vulnerability has been resolved: netfilter: nf_reject: don't leak dst refcount for loopback packets recent patches to add a WARN() when replacing skb dst entry found an old bug: WARNING: include/linux/skbuff.h:1165 skb_dst_check_unset include/linux/skbuff.h:1164 [inline] WARNING: include/linux/skbuff.h:1165 skb_dst_set include/linux/skbuff.h:1210 [inline] WARNING: include/linux/skbuff.h:1165 nf_reject_fill_skb_dst+0x2a4/0x330 net/ipv4/netfilter/nf_reject_ipv4.c:234 [..] Call Trace: nf_send_unreach+0x17b/0x6e0 net/ipv4/netfilter/nf_reject_ipv4.c:325 nft_reject_inet_eval+0x4bc/0x690 net/netfilter/nft_reject_inet.c:27 expr_call_ops_eval net/netfilter/nf_tables_core.c:237 [inline] .. This is because blamed commit forgot about loopback packets. Such packets already have a dst_entry attached, even at PRE_ROUTING stage. Instead of checking hook just check if the skb already has a route attached to it.

Affected

36 ranges· showing 25
VendorProductVersion rangeFixed in
debiandebian_linux
debianlinux< linux 6.1.153-1 (bookworm)linux 6.1.153-1 (bookworm)
debianlinux-6.1< linux 6.1.153-1 (bookworm)linux 6.1.153-1 (bookworm)
linuxlinux
linuxlinux>= f53b9b0bdc59c0823679f2e3214e0d538f5951b9 < 7b8b503c06274ef3c6c1a107743f1ec0d0a53ef87b8b503c06274ef3c6c1a107743f1ec0d0a53ef8
linuxlinux>= f53b9b0bdc59c0823679f2e3214e0d538f5951b9 < 82ef97abf22790182f7d433c74960dfd61b99c3382ef97abf22790182f7d433c74960dfd61b99c33
linuxlinux>= f53b9b0bdc59c0823679f2e3214e0d538f5951b9 < b7a885ba25960c91db237c3f83b4285156789bceb7a885ba25960c91db237c3f83b4285156789bce
linuxlinux>= f53b9b0bdc59c0823679f2e3214e0d538f5951b9 < a0a3ace2a57887dac1e7c9a724846040c3e31868a0a3ace2a57887dac1e7c9a724846040c3e31868
linuxlinux>= f53b9b0bdc59c0823679f2e3214e0d538f5951b9 < 51e8531371f90bee742c63775c9a568e5d6bf3c551e8531371f90bee742c63775c9a568e5d6bf3c5
linuxlinux>= f53b9b0bdc59c0823679f2e3214e0d538f5951b9 < b32e1590a8d22cf7d7f965e46d5576051acf8e42b32e1590a8d22cf7d7f965e46d5576051acf8e42
linuxlinux>= f53b9b0bdc59c0823679f2e3214e0d538f5951b9 < 91a79b792204313153e1bdbbe5acbfc28903b3a591a79b792204313153e1bdbbe5acbfc28903b3a5
linuxlinux_kernel
linuxlinux_kernel>= 0 < 5.10.244-15.10.244-1
linuxlinux_kernel>= 0 < 6.1.153-16.1.153-1
linuxlinux_kernel>= 0 < 6.12.48-16.12.48-1
linuxlinux_kernel>= 0 < 6.16.5-16.16.5-1
linuxlinux_kernel>= 0 < 5.15.0-163.1735.15.0-163.173
linuxlinux_kernel>= 0 < 6.8.0-100.1006.8.0-100.100
linuxlinux_kernel>= 5.11 < 5.15.1905.15.190
linuxlinux_kernel>= 5.16 < 6.1.1496.1.149
linuxlinux_kernel>= 5.9 < 5.10.2415.10.241
linuxlinux_kernel>= 6.13 < 6.16.46.16.4
linuxlinux_kernel>= 6.2 < 6.6.1036.6.103
linuxlinux_kernel>= 6.7 < 6.12.446.12.44
msrcazl3_kernel_6.6.96.2-1_on_azure_linux_3.0

CVSS provenance

nvdv3.15.5MEDIUMCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
osv5.5MEDIUM