CVE-2025-40206 — Uncontrolled Recursion in Linux
Severity
3.2LOWOSV
No vectorEPSS
0.0%
top 92.16%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedNov 12
Latest updateApr 9
Description
In the Linux kernel, the following vulnerability has been resolved:
netfilter: nft_objref: validate objref and objrefmap expressions
Referencing a synproxy stateful object from OUTPUT hook causes kernel
crash due to infinite recursive calls:
BUG: TASK stack guard page was hit at 000000008bda5b8c (stack is 000000003ab1c4a5..00000000494d8b12)
[...]
Call Trace:
__find_rr_leaf+0x99/0x230
fib6_table_lookup+0x13b/0x2d0
ip6_pol_route+0xa4/0x400
fib6_rule_lookup+0x156/0x240
ip6_route_output_flags+0xc…
Affected Packages6 packages
▶CVEListV5linux/linuxee394f96ad7517fbc0de9106dcc7ce9efb14f264 — 0028e0134c64d9ed21728341a74fcfc59cd0f944+4