CVE-2025-39764

netfilter: ctnetlink: remove refcounting in expectation dumpers

References

Notes

 carnil> Introduced in cf6994c2b981 ("[NETFILTER]: nf_conntrack_netlink: sync
 carnil> expectation dumping with conntrack table dumping")
 carnil> e844a928431f ("netfilter: ctnetlink: allow to dump expectation per master
 carnil> conntrack"). Vulnerable versions: 2.6.23.

Bugs

Status

Branch Status
upstream released (6.17-rc2) [1492e3dcb2be3aa46d1963da96aa9593e4e4db5a]
6.18-upstream-stable N/A "Fixed before branching point"
6.17-upstream-stable N/A "Fixed before branching point"
6.16-upstream-stable released (6.16.2) [a4d634ded4d3d400f115d84f654f316f249531c9]
6.12-upstream-stable needed
6.6-upstream-stable needed
6.1-upstream-stable needed
5.10-upstream-stable needed
sid released (6.16.3-1)
6.12-trixie-security needed
6.1-bookworm-security needed
5.10-bullseye-security needed