cbcvebase.
CVE-2025-39764
published 2025-09-11

CVE-2025-39764: In the Linux kernel, the following vulnerability has been resolved: netfilter: ctnetlink: remove refcounting in expectation dumpers Same pattern as previous…

PriorityP418medium5.5CVSS 3.1
AVLACLPRLUINSUCNINAH
EPSS
0.15%
5.0th percentile
In the Linux kernel, the following vulnerability has been resolved: netfilter: ctnetlink: remove refcounting in expectation dumpers Same pattern as previous patch: do not keep the expectation object alive via refcount, only store a cookie value and then use that as the skip hint for dump resumption. AFAICS this has the same issue as the one resolved in the conntrack dumper, when we do if (!refcount_inc_not_zero(&exp->use)) to increment the refcount, there is a chance that exp == last, which causes a double-increment of the refcount and subsequent memory leak.

Affected

30 ranges· showing 25
VendorProductVersion rangeFixed in
debianlinux< linux 6.16.3-1 (forky)linux 6.16.3-1 (forky)
linuxlinux
linuxlinux>= cf6994c2b9812a9f02b99e89df411ffc5db9c779 < b05500444b8eb97644efdd180839a04a706be97cb05500444b8eb97644efdd180839a04a706be97c
linuxlinux>= cf6994c2b9812a9f02b99e89df411ffc5db9c779 < bada48ad5b0590e318d0f79636ff62a2ef9f4955bada48ad5b0590e318d0f79636ff62a2ef9f4955
linuxlinux>= cf6994c2b9812a9f02b99e89df411ffc5db9c779 < 64b7684042246e3238464c66894e30ba30c7e85164b7684042246e3238464c66894e30ba30c7e851
linuxlinux>= cf6994c2b9812a9f02b99e89df411ffc5db9c779 < 9e5021a906532ca16e2aac69c0607711e1c70b1f9e5021a906532ca16e2aac69c0607711e1c70b1f
linuxlinux>= cf6994c2b9812a9f02b99e89df411ffc5db9c779 < 078d33c95bf534d37aa04269d1ae6158e20082d5078d33c95bf534d37aa04269d1ae6158e20082d5
linuxlinux>= cf6994c2b9812a9f02b99e89df411ffc5db9c779 < a4d634ded4d3d400f115d84f654f316f249531c9a4d634ded4d3d400f115d84f654f316f249531c9
linuxlinux>= cf6994c2b9812a9f02b99e89df411ffc5db9c779 < 1492e3dcb2be3aa46d1963da96aa9593e4e4db5a1492e3dcb2be3aa46d1963da96aa9593e4e4db5a
linuxlinux_kernel
linuxlinux_kernel>= 0 < 6.16.3-16.16.3-1
linuxlinux_kernel>= 2.6.23 < 6.16.26.16.2
msrcazl3_kernel_6.6.104.2-4_on_azure_linux_3.0
msrcazl3_kernel_6.6.112.1-2_on_azure_linux_3.0
msrcazl3_kernel_6.6.117.1-1_on_azure_linux_3.0
msrcazl3_kernel_6.6.119.3-1_on_azure_linux_3.0
msrcazl3_kernel_6.6.119.3-3_on_azure_linux_3.0
msrcazl3_kernel_6.6.121.1-1_on_azure_linux_3.0
msrcazl3_kernel_6.6.126.1-1_on_azure_linux_3.0
msrcazl3_kernel_6.6.96.2-2_on_azure_linux_3.0
msrccbl2_kernel_5.15.186.1-1_on_cbl_mariner_2.0
msrccbl2_kernel_5.15.200.1-1_on_cbl_mariner_2.0
msrccbl2_kernel_5.15.202.1-1_on_cbl_mariner_2.0
ubuntulinux
ubuntulinux-gcp

CVSS provenance

nvdv3.15.5MEDIUMCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
osv5.5MEDIUM
vendor_debian5.5MEDIUM
vendor_msrc5.5MEDIUM
vendor_redhat5.5MEDIUM
vendor_ubuntu2.0LOW
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.