PT-2025-46763 · Linux+3 · Linux Kernel+3
Published
2025-10-08
·
Updated
2026-05-07
·
CVE-2025-40206
CVSS v2.0
4.6
Medium
| Vector | AV:L/AC:L/Au:S/C:N/I:N/A:C |
Name of the Vulnerable Software and Affected Versions
Linux kernel (affected versions not specified)
Description
The Linux kernel contains a flaw within the netfilter module related to the validation of objref and objrefmap expressions. Specifically, referencing a synproxy stateful object from the OUTPUT hook can lead to a kernel crash due to infinite recursive calls. This issue occurs because of insufficient validation when handling these expressions. Attempting to reference a synproxy object in the OUTPUT hook now results in an 'Operation not supported' error. The vulnerability impacts the
nft do chain and nft do chain inet functions.Recommendations
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Exploit
Uncontrolled Recursion
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Debian
Linuxmint
Linux Kernel
Ubuntu