PT-2026-4476 · Linux+2 · Linux Kernel+2

Published

2025-01-01

·

Updated

2026-06-16

·

CVE-2025-71160

CVSS v3.1

5.5

Medium

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions Linux kernel (affected versions not specified)
Description The Linux kernel's netfilter module contains an issue within the nf tables component related to chain validation. The vulnerability can lead to CPU soft lock-ups during nft chain validate() processing. The issue arises from unnecessary re-validation of chains when traversing the table graph, potentially impacting performance and system stability. The problem occurs because the system revalidates chains even when they have already been checked, leading to redundant processing. This is particularly relevant when dealing with complex chain structures involving jumps. The validation process also ensures that expressions are called from valid base chains, such as the masquerade expression being limited to NAT postrouting base chains.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

AZL-75126
AZL-78434
CVE-2025-71160
ECHO-548B-80CE-E027
OESA-2026-2581
USN-8278-1
USN-8278-2
USN-8289-1
USN-8289-2
USN-8296-1
USN-8296-2
USN-8393-1
USN-8440-1

Affected Products

Linuxmint
Linux Kernel
Ubuntu