PT-2025-31069 · Linux+9 · Linux Kernel+9

Published

2025-07-16

·

Updated

2026-04-20

·

CVE-2025-38472

CVSS v3.1

5.5

Medium

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions Linux kernel (affected versions not specified)
Description A crash in the conntrack component of the Linux kernel was reported due to the removal of an uninitialized entry. The issue occurs when an expired conntrack entry is deleted from the hash bucket list, potentially leading to a crash within the nf ct delete from lists function. The root cause is a race condition where a conntrack entry can be re-initialized while still being referenced, resulting in a partially initialized state and an incorrect hash value. This can occur when a CPU finds an expired entry, another CPU preempts it, and the entry is re-initialized before the first CPU can complete the deletion process. The fix involves moving the assignment of the IPS CONFIRMED flag after the table insertion and before the unlock, and modifying nf ct should gc() to check the confirmed bit first.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

DoS

Use of Uninitialized Resource

Allocation of Resources Without Limits

Weakness Enumeration

Related Identifiers

ALSA-2025:15005
ALSA-2025:16880
AZL-65892
BDU:2025-10797
CVE-2025-38472
DLA-4328-1
DSA-5973-1
DSA-5975-1
ECHO-FFC8-ED8F-C367
INFSA-2025_16880
MGASA-2025-0218
MGASA-2025-0219
OPENSUSE-SU-2025:20081-1
RHSA-2025:16880
RHSA-2025_16880
SUSE-SU-2025:03272-1
SUSE-SU-2025:03290-1
SUSE-SU-2025:03301-1
SUSE-SU-2025:03382-1
SUSE-SU-2025:03602-1
SUSE-SU-2025:03633-1
SUSE-SU-2025:03634-1
SUSE-SU-2025:20653-1
SUSE-SU-2025:20669-1
SUSE-SU-2025:20739-1
SUSE-SU-2025:20756-1
SUSE-SU-2025:21074-1
SUSE-SU-2025:21139-1
SUSE-SU-2025:21179-1
SUSE-SU-2025_03272-1
SUSE-SU-2025_03290-1
SUSE-SU-2025_03301-1
SUSE-SU-2025_03382-1
USN-7879-1
USN-7879-2
USN-7879-3
USN-7879-4
USN-7880-1
USN-7934-1
USN-8028-1
USN-8028-2
USN-8028-3
USN-8028-4
USN-8028-5
USN-8028-6
USN-8028-7
USN-8028-8
USN-8031-1
USN-8031-2
USN-8031-3
USN-8052-1
USN-8052-2
USN-8074-1
USN-8074-2
USN-8126-1

Affected Products

Almalinux
Astra Linux
Debian
Linuxmint
Linux Kernel
Red Hat
Red Os
Rocky Linux
Suse
Ubuntu