CVE-2025-21959

CVSS 3.1 Score 5.5 of 10 (medium)

Details

Published Apr 1, 2025
Updated: Apr 14, 2025
CWE ID 908

Summary

CVE-2025-21959: A vulnerability in the Linux kernel's netfilter subsystem, specifically in the nf_conncount module, has been addressed. The issue was caused by the lack of initialization of `conn->cpu` and `conn->jiffies32` in the `count_tree()` function, which led to uninitialized values being used in various netfilter functions. The vulnerability could result in a Kernel Address Sanitizer (KMSAN) error. The issue was introduced during the split of the `insert_tree()` and `count_tree()` functions and was discovered during the allocation of the struct nf_conncount_tuple.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share