DEBIAN-CVE-2025-38732
In the Linux kernel, the following vulnerability has been resolved: netfilter: nf_reject: don't leak dst refcount for loopback packets recent patches to add a WARN() when replacing skb dst entry found an old bug: WARNING: include/linux/skbuff.h:1165 skb_dst_check_unset include/linux/skbuff.h:1164 [inline] WARNING: include/linux/skbuff.h:1165 skb_dst_set include/linux/skbuff.h:1210 [inline] WARNING: include/linux/skbuff.h:1165 nf_reject_fill_skb_dst+0x2a4/0x330 net/ipv4/netfilter/nf_reject_ipv4.c:234 [..] Call Trace: nf_send_unreach+0x17b/0x6e0 net/ipv4/netfilter/nf_reject_ipv4.c:325 nft_reject_inet_eval+0x4bc/0x690 net/netfilter/nft_reject_inet.c:27 expr_call_ops_eval net/netfilter/nf_tables_core.c:237 [inline] .. This is because blamed commit forgot about loopback packets. Such packets already have a dst_entry attached, even at PRE_ROUTING stage. Instead of checking hook just check if the skb already has a route attached to it.
Risk Scores
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Debian:11 | linux | 5.10.218-1, 5.10.84-1, 5.10.70-1 |
| Debian:11 | linux-6.1 | 6.1.137-1, 6.1.129-1, 6.1.128-1 |
| Debian:12 | linux | 6.1.38-3, 0, 6.1.106-1 |
| Debian:14 | linux | 6.12.38-1, 6.12.43-1, * |
| Debian:13 | linux | 6.12.43-1, 6.12.41-1, 6.12.38-1 |
Exploit Intelligence
- 4081.3.6.yml (github-poc)
Timeline
- Sep 5, 2025 CVE Published
- Apr 28, 2026 CVE Updated