CVE-2025-21959
CVSS 3.1 Score 5.5 of 10 (medium)
Details
Summary
CVE-2025-21959: A vulnerability in the Linux kernel's netfilter subsystem, specifically in the nf_conncount module, has been addressed. The issue was caused by the lack of initialization of `conn->cpu` and `conn->jiffies32` in the `count_tree()` function, which led to uninitialized values being used in various netfilter functions. The vulnerability could result in a Kernel Address Sanitizer (KMSAN) error. The issue was introduced during the split of the `insert_tree()` and `count_tree()` functions and was discovered during the allocation of the struct nf_conncount_tuple.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.