{ "dataType": "CVE_RECORD", "dataVersion": "5.2", "cveMetadata": { "cveId": "CVE-2025-40206", "assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67", "state": "PUBLISHED", "assignerShortName": "Linux", "dateReserved": "2025-04-16T07:20:57.179Z", "datePublished": "2025-11-12T21:56:35.675Z", "dateUpdated": "2026-08-23T12:45:25.956Z" }, "containers": { "cna": { "providerMetadata": { "orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67", "shortName": "Linux", "dateUpdated": "2026-08-23T12:45:25.956Z" }, "descriptions": [ { "lang": "en", "value": "In the Linux kernel, the following vulnerability has been resolved:\n\nnetfilter: nft_objref: validate objref and objrefmap expressions\n\nReferencing a synproxy stateful object from OUTPUT hook causes kernel\ncrash due to infinite recursive calls:\n\nBUG: TASK stack guard page was hit at 000000008bda5b8c (stack is 000000003ab1c4a5..00000000494d8b12)\n[...]\nCall Trace:\n __find_rr_leaf+0x99/0x230\n fib6_table_lookup+0x13b/0x2d0\n ip6_pol_route+0xa4/0x400\n fib6_rule_lookup+0x156/0x240\n ip6_route_output_flags+0xc6/0x150\n __nf_ip6_route+0x23/0x50\n synproxy_send_tcp_ipv6+0x106/0x200\n synproxy_send_client_synack_ipv6+0x1aa/0x1f0\n nft_synproxy_do_eval+0x263/0x310\n nft_do_chain+0x5a8/0x5f0 [nf_tables\n nft_do_chain_inet+0x98/0x110\n nf_hook_slow+0x43/0xc0\n __ip6_local_out+0xf0/0x170\n ip6_local_out+0x17/0x70\n synproxy_send_tcp_ipv6+0x1a2/0x200\n synproxy_send_client_synack_ipv6+0x1aa/0x1f0\n[...]\n\nImplement objref and objrefmap expression validate functions.\n\nCurrently, only NFT_OBJECT_SYNPROXY object type requires validation.\nThis will also handle a jump to a chain using a synproxy object from the\nOUTPUT hook.\n\nNow when trying to reference a synproxy object in the OUTPUT hook, nft\nwill produce the following error:\n\nsynproxy_crash.nft: Error: Could not process rule: Operation not supported\n synproxy name mysynproxy\n ^^^^^^^^^^^^^^^^^^^^^^^^" } ], "metrics": [ { "cvssV3_1": { "version": "3.1", "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H", "baseScore": 7.8, "baseSeverity": "HIGH" }, "scenarios": [ { "lang": "en", "value": "AV:L - The flaw is enabled through an nftables ruleset installed over the NFNL_SUBSYS_NFTABLES netlink socket, and triggered by a locally-generated TCP SYN traversing the OUTPUT hook. Per netfilter/nftables convention this is a local attack surface, not a remotely reachable one.\nAC:L - Exploitation is fully deterministic — add a synproxy object reference to an OUTPUT base chain and emit any TCP SYN; there is no race, no memory-layout dependency, and no bound on the recursion depth. CONFIG_NFT_SYNPROXY is standard and autoloadable on distribution kernels.\nPR:L - nfnetlink_rcv checks netlink_net_capable(skb, CAP_NET_ADMIN), which evaluates against the network namespace's owning user namespace, so any unprivileged local user obtains it via `unshare -Urn`; nft_synproxy_do_init imposes no init_user_ns requirement. The resulting stack overflow is not confined to the namespace and takes down the host.\nUI:N - The attacker performs both steps — installing the rule and emitting the triggering SYN — with no action required from any other user or administrator.\nS:U - The recursion, the stack exhaustion, and the resulting panic all occur within the kernel's own security authority; no hypervisor, IOMMU, or other trust boundary is crossed.\nC:H - The unbounded recursion exhausts the kernel stack, and on the many embedded/IoT/automotive configurations lacking CONFIG_VMAP_STACK (arm32 without ARM_HAS_GROUP_RELOCS, and architectures with no VMAP_STACK support) it runs past the stack into adjacent kernel pages rather than into a guard page, corrupting neighbouring structures that can be leveraged for kernel memory disclosure.\nI:H - On those same non-VMAP_STACK configurations the overrun writes attacker-influenced frame contents — struct flowi6 built from the attacker's SYN addresses/ports, synproxy_options with attacker-chosen MSS/wscale/timestamps, and nft_regs — into adjacent kernel memory, and on architectures where thread_info sits at the stack base it clobbers that first, yielding an exploitable corruption primitive.\nA:H - The infinite recursion reliably exhausts the kernel stack and hits the guard page, producing an immediate kernel panic as shown in the reporter's trace. This is a complete denial of service triggerable at will by an unprivileged local user." } ] } ], "affected": [ { "product": "Linux", "vendor": "Linux", "defaultStatus": "unaffected", "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git", "programFiles": [ "net/netfilter/nft_objref.c" ], "versions": [ { "version": "ee394f96ad7517fbc0de9106dcc7ce9efb14f264", "lessThan": "f31bcea12222a26d6f151df9c4a6d21f2eec1724", "status": "affected", "versionType": "git" }, { "version": "ee394f96ad7517fbc0de9106dcc7ce9efb14f264", "lessThan": "0028e0134c64d9ed21728341a74fcfc59cd0f944", "status": "affected", "versionType": "git" }, { "version": "ee394f96ad7517fbc0de9106dcc7ce9efb14f264", "lessThan": "7ea55a44493a5a36c3b3293b88bbe4841f9dbaf0", "status": "affected", "versionType": "git" }, { "version": "ee394f96ad7517fbc0de9106dcc7ce9efb14f264", "lessThan": "4c1cf72ec10be5a9ad264650cadffa1fbce6fabd", "status": "affected", "versionType": "git" }, { "version": "ee394f96ad7517fbc0de9106dcc7ce9efb14f264", "lessThan": "f359b809d54c6e3dd1d039b97e0b68390b0e53e4", "status": "affected", "versionType": "git" } ] }, { "product": "Linux", "vendor": "Linux", "defaultStatus": "affected", "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git", "programFiles": [ "net/netfilter/nft_objref.c" ], "versions": [ { "version": "5.4", "status": "affected" }, { "version": "0", "lessThan": "5.4", "status": "unaffected", "versionType": "semver" }, { "version": "6.1.184", "lessThanOrEqual": "6.1.*", "status": "unaffected", "versionType": "semver" }, { "version": "6.6.113", "lessThanOrEqual": "6.6.*", "status": "unaffected", "versionType": "semver" }, { "version": "6.12.54", "lessThanOrEqual": "6.12.*", "status": "unaffected", "versionType": "semver" }, { "version": "6.17.4", "lessThanOrEqual": "6.17.*", "status": "unaffected", "versionType": "semver" }, { "version": "6.18", "lessThanOrEqual": "*", "status": "unaffected", "versionType": "original_commit_for_fix" } ] } ], "cpeApplicability": [ { "nodes": [ { "operator": "OR", "negate": false, "cpeMatch": [ { "vulnerable": true, "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*", "versionStartIncluding": "5.4", "versionEndExcluding": "6.1.184" }, { "vulnerable": true, "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*", "versionStartIncluding": "5.4", "versionEndExcluding": "6.6.113" }, { "vulnerable": true, "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*", "versionStartIncluding": "5.4", "versionEndExcluding": "6.12.54" }, { "vulnerable": true, "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*", "versionStartIncluding": "5.4", "versionEndExcluding": "6.17.4" }, { "vulnerable": true, "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*", "versionStartIncluding": "5.4", "versionEndExcluding": "6.18" } ] } ] } ], "references": [ { "url": "https://git.kernel.org/stable/c/f31bcea12222a26d6f151df9c4a6d21f2eec1724" }, { "url": "https://git.kernel.org/stable/c/0028e0134c64d9ed21728341a74fcfc59cd0f944" }, { "url": "https://git.kernel.org/stable/c/7ea55a44493a5a36c3b3293b88bbe4841f9dbaf0" }, { "url": "https://git.kernel.org/stable/c/4c1cf72ec10be5a9ad264650cadffa1fbce6fabd" }, { "url": "https://git.kernel.org/stable/c/f359b809d54c6e3dd1d039b97e0b68390b0e53e4" } ], "title": "netfilter: nft_objref: validate objref and objrefmap expressions", "x_generator": { "engine": "bippy-1.2.0" } } } }