{"dataType":"CVE_RECORD","dataVersion":"5.2","cveMetadata":{"cveId":"CVE-2025-40206","assignerOrgId":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","state":"PUBLISHED","assignerShortName":"Linux","dateReserved":"2025-04-16T07:20:57.179Z","datePublished":"2025-11-12T21:56:35.675Z","dateUpdated":"2026-08-23T12:45:25.956Z"},"containers":{"cna":{"providerMetadata":{"orgId":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","shortName":"Linux","dateUpdated":"2026-08-23T12:45:25.956Z"},"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nnetfilter: nft_objref: validate objref and objrefmap expressions\n\nReferencing a synproxy stateful object from OUTPUT hook causes kernel\ncrash due to infinite recursive calls:\n\nBUG: TASK stack guard page was hit at 000000008bda5b8c (stack is 000000003ab1c4a5..00000000494d8b12)\n[...]\nCall Trace:\n __find_rr_leaf+0x99/0x230\n fib6_table_lookup+0x13b/0x2d0\n ip6_pol_route+0xa4/0x400\n fib6_rule_lookup+0x156/0x240\n ip6_route_output_flags+0xc6/0x150\n __nf_ip6_route+0x23/0x50\n synproxy_send_tcp_ipv6+0x106/0x200\n synproxy_send_client_synack_ipv6+0x1aa/0x1f0\n nft_synproxy_do_eval+0x263/0x310\n nft_do_chain+0x5a8/0x5f0 [nf_tables\n nft_do_chain_inet+0x98/0x110\n nf_hook_slow+0x43/0xc0\n __ip6_local_out+0xf0/0x170\n ip6_local_out+0x17/0x70\n synproxy_send_tcp_ipv6+0x1a2/0x200\n synproxy_send_client_synack_ipv6+0x1aa/0x1f0\n[...]\n\nImplement objref and objrefmap expression validate functions.\n\nCurrently, only NFT_OBJECT_SYNPROXY object type requires validation.\nThis will also handle a jump to a chain using a synproxy object from the\nOUTPUT hook.\n\nNow when trying to reference a synproxy object in the OUTPUT hook, nft\nwill produce the following error:\n\nsynproxy_crash.nft: Error: Could not process rule: Operation not supported\n  synproxy name mysynproxy\n  ^^^^^^^^^^^^^^^^^^^^^^^^"}],"metrics":[{"cvssV3_1":{"version":"3.1","vectorString":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","baseScore":7.8,"baseSeverity":"HIGH"},"scenarios":[{"lang":"en","value":"AV:L - The flaw is enabled through an nftables ruleset installed over the NFNL_SUBSYS_NFTABLES netlink socket, and triggered by a locally-generated TCP SYN traversing the OUTPUT hook. Per netfilter/nftables convention this is a local attack surface, not a remotely reachable one.\nAC:L - Exploitation is fully deterministic — add a synproxy object reference to an OUTPUT base chain and emit any TCP SYN; there is no race, no memory-layout dependency, and no bound on the recursion depth. CONFIG_NFT_SYNPROXY is standard and autoloadable on distribution kernels.\nPR:L - nfnetlink_rcv checks netlink_net_capable(skb, CAP_NET_ADMIN), which evaluates against the network namespace's owning user namespace, so any unprivileged local user obtains it via `unshare -Urn`; nft_synproxy_do_init imposes no init_user_ns requirement. The resulting stack overflow is not confined to the namespace and takes down the host.\nUI:N - The attacker performs both steps — installing the rule and emitting the triggering SYN — with no action required from any other user or administrator.\nS:U - The recursion, the stack exhaustion, and the resulting panic all occur within the kernel's own security authority; no hypervisor, IOMMU, or other trust boundary is crossed.\nC:H - The unbounded recursion exhausts the kernel stack, and on the many embedded/IoT/automotive configurations lacking CONFIG_VMAP_STACK (arm32 without ARM_HAS_GROUP_RELOCS, and architectures with no VMAP_STACK support) it runs past the stack into adjacent kernel pages rather than into a guard page, corrupting neighbouring structures that can be leveraged for kernel memory disclosure.\nI:H - On those same non-VMAP_STACK configurations the overrun writes attacker-influenced frame contents — struct flowi6 built from the attacker's SYN addresses/ports, synproxy_options with attacker-chosen MSS/wscale/timestamps, and nft_regs — into adjacent kernel memory, and on architectures where thread_info sits at the stack base it clobbers that first, yielding an exploitable corruption primitive.\nA:H - The infinite recursion reliably exhausts the kernel stack and hits the guard page, producing an immediate kernel panic as shown in the reporter's trace. This is a complete denial of service triggerable at will by an unprivileged local user."}]}],"affected":[{"product":"Linux","vendor":"Linux","defaultStatus":"unaffected","repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","programFiles":["net/netfilter/nft_objref.c"],"versions":[{"version":"ee394f96ad7517fbc0de9106dcc7ce9efb14f264","lessThan":"f31bcea12222a26d6f151df9c4a6d21f2eec1724","status":"affected","versionType":"git"},{"version":"ee394f96ad7517fbc0de9106dcc7ce9efb14f264","lessThan":"0028e0134c64d9ed21728341a74fcfc59cd0f944","status":"affected","versionType":"git"},{"version":"ee394f96ad7517fbc0de9106dcc7ce9efb14f264","lessThan":"7ea55a44493a5a36c3b3293b88bbe4841f9dbaf0","status":"affected","versionType":"git"},{"version":"ee394f96ad7517fbc0de9106dcc7ce9efb14f264","lessThan":"4c1cf72ec10be5a9ad264650cadffa1fbce6fabd","status":"affected","versionType":"git"},{"version":"ee394f96ad7517fbc0de9106dcc7ce9efb14f264","lessThan":"f359b809d54c6e3dd1d039b97e0b68390b0e53e4","status":"affected","versionType":"git"}]},{"product":"Linux","vendor":"Linux","defaultStatus":"affected","repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","programFiles":["net/netfilter/nft_objref.c"],"versions":[{"version":"5.4","status":"affected"},{"version":"0","lessThan":"5.4","status":"unaffected","versionType":"semver"},{"version":"6.1.184","lessThanOrEqual":"6.1.*","status":"unaffected","versionType":"semver"},{"version":"6.6.113","lessThanOrEqual":"6.6.*","status":"unaffected","versionType":"semver"},{"version":"6.12.54","lessThanOrEqual":"6.12.*","status":"unaffected","versionType":"semver"},{"version":"6.17.4","lessThanOrEqual":"6.17.*","status":"unaffected","versionType":"semver"},{"version":"6.18","lessThanOrEqual":"*","status":"unaffected","versionType":"original_commit_for_fix"}]}],"cpeApplicability":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"5.4","versionEndExcluding":"6.1.184"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"5.4","versionEndExcluding":"6.6.113"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"5.4","versionEndExcluding":"6.12.54"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"5.4","versionEndExcluding":"6.17.4"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"5.4","versionEndExcluding":"6.18"}]}]}],"references":[{"url":"https://git.kernel.org/stable/c/f31bcea12222a26d6f151df9c4a6d21f2eec1724"},{"url":"https://git.kernel.org/stable/c/0028e0134c64d9ed21728341a74fcfc59cd0f944"},{"url":"https://git.kernel.org/stable/c/7ea55a44493a5a36c3b3293b88bbe4841f9dbaf0"},{"url":"https://git.kernel.org/stable/c/4c1cf72ec10be5a9ad264650cadffa1fbce6fabd"},{"url":"https://git.kernel.org/stable/c/f359b809d54c6e3dd1d039b97e0b68390b0e53e4"}],"title":"netfilter: nft_objref: validate objref and objrefmap expressions","x_generator":{"engine":"bippy-1.2.0"}}}}