CVE-2025-68245
In the Linux kernel, the following vulnerability has been resolved:
net: netpoll: fix incorrect refcount handling causing incorrect cleanup
commit efa95b01da18 ("netpoll: fix use after free") incorrectly ignored the refcount and prematurely set dev->npinfo to NULL during netpoll cleanup, leading to improper behavior and memory leaks.
Scenario causing lack of proper cleanup:
Revert commit efa95b01da18 ("netpoll: fix use after free") and adds clarifying comments emphasizing that npinfo cleanup should only happen once the refcount reaches zero, ensuring stable and correct netpoll behavior.
Detalles técnicos trazas, registros y código del informe original
1) A netpoll is associated with a NIC (e.g., eth0) and netdev->npinfo is
allocated, and refcnt = 1
- Keep in mind that npinfo is shared among all netpoll instances. In
this case, there is just one.
2) Another netpoll is also associated with the same NIC and
npinfo->refcnt += 1.
- Now dev->npinfo->refcnt = 2;
- There is just one npinfo associated to the netdev.
3) When the first netpolls goes to clean up:
- The first cleanup succeeds and clears np->dev->npinfo, ignoring
refcnt.
- It basically calls `RCU_INIT_POINTER(np->dev->npinfo, NULL);`
- Set dev->npinfo = NULL, without proper cleanup
- No ->ndo_netpoll_cleanup() is either called
4) Now the second target tries to clean up
- The second cleanup fails because np->dev->npinfo is already NULL.
* In this case, ops->ndo_netpoll_cleanup() was never called, and
the skb pool is not cleaned as well (for the second netpoll
instance)
- This leaks npinfo and skbpool skbs, which is clearly reported by
kmemleak.CVSS
NVD no ha asignado puntuación CVSS a esta CVE (habitual desde el cambio de política de abril de 2026).
Probabilidad de explotación (EPSS)
- Probabilidad de explotación en los próximos 30 días: 0.20%
- Percentil entre todas las CVEs puntuadas: 9
- Fecha de la puntuación: 5/10/2026
EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).
Tecnologías afectadas (1)
⚠ Inferidas por IA a partir de la descripción — NVD aún no ha analizado esta CVE; no son CPE verificados.
Referencias
- https://git.kernel.org/stable/c/49c8d2c1f94cc2f4d1a108530d7ba52614b874c2
- https://git.kernel.org/stable/c/4afd4ebbad52aa146838ec23082ba393e426a2bb
- https://git.kernel.org/stable/c/890472d6fbf062e6de7fdd56642cb305ab79d669
- https://git.kernel.org/stable/c/8e6a50edad11e3e1426e4c29e7aa6201f3468ac2
- https://git.kernel.org/stable/c/9a51b5ccd1c79afec1c03a4e1e6688da52597556
- https://git.kernel.org/stable/c/9b0bb18b4b9dc017c1825a2c5e763615e34a1593
- https://git.kernel.org/stable/c/c645693180a98606c430825223d2029315d85e9d
- https://git.kernel.org/stable/c/c79a6d9da29219616b118a3adce9a14cd30f9bd0
JSON original (NVD)
Mostrar
{
"id": "CVE-2025-68245",
"cveTags": [],
"metrics": {},
"affected": [
{
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"affectedData": [
{
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"product": "Linux",
"versions": [
{
"status": "affected",
"version": "efa95b01da18ad22af62f6d99a3243f3be8fd264",
"lessThan": "8e6a50edad11e3e1426e4c29e7aa6201f3468ac2",
"versionType": "git"
},
{
"status": "affected",
"version": "efa95b01da18ad22af62f6d99a3243f3be8fd264",
"lessThan": "9b0bb18b4b9dc017c1825a2c5e763615e34a1593",
"versionType": "git"
},
{
"status": "affected",
"version": "efa95b01da18ad22af62f6d99a3243f3be8fd264",
"lessThan": "890472d6fbf062e6de7fdd56642cb305ab79d669",
"versionType": "git"
},
{
"status": "affected",
"version": "efa95b01da18ad22af62f6d99a3243f3be8fd264",
"lessThan": "4afd4ebbad52aa146838ec23082ba393e426a2bb",
"versionType": "git"
},
{
"status": "affected",
"version": "efa95b01da18ad22af62f6d99a3243f3be8fd264",
"lessThan": "c645693180a98606c430825223d2029315d85e9d",
"versionType": "git"
},
{
"status": "affected",
"version": "efa95b01da18ad22af62f6d99a3243f3be8fd264",
"lessThan": "c79a6d9da29219616b118a3adce9a14cd30f9bd0",
"versionType": "git"
},
{
"status": "affected",
"version": "efa95b01da18ad22af62f6d99a3243f3be8fd264",
"lessThan": "9a51b5ccd1c79afec1c03a4e1e6688da52597556",
"versionType": "git"
},
{
"status": "affected",
"version": "efa95b01da18ad22af62f6d99a3243f3be8fd264",
"lessThan": "49c8d2c1f94cc2f4d1a108530d7ba52614b874c2",
"versionType": "git"
}
],
"programFiles": [
"net/core/netpoll.c"
],
"defaultStatus": "unaffected"
},
{
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"product": "Linux",
"versions": [
{
"status": "affected",
"version": "3.17"
},
{
"status": "unaffected",
"version": "0",
"lessThan": "3.17",
"versionType": "semver"
},
{
"status": "unaffected",
"version": "5.4.302",
"versionType": "semver",
"lessThanOrEqual": "5.4.*"
},
{
"status": "unaffected",
"version": "5.10.247",
"versionType": "semver",
"lessThanOrEqual": "5.10.*"
},
{
"status": "unaffected",
"version": "5.15.197",
"versionType": "semver",
"lessThanOrEqual": "5.15.*"
},
{
"status": "unaffected",
"version": "6.1.159",
"versionType": "semver",
"lessThanOrEqual": "6.1.*"
},
{
"status": "unaffected",
"version": "6.6.117",
"versionType": "semver",
"lessThanOrEqual": "6.6.*"
},
{
"status": "unaffected",
"version": "6.12.59",
"versionType": "semver",
"lessThanOrEqual": "6.12.*"
},
{
"status": "unaffected",
"version": "6.17.9",
"versionType": "semver",
"lessThanOrEqual": "6.17.*"
},
{
"status": "unaffected",
"version": "6.18",
"versionType": "original_commit_for_fix",
"lessThanOrEqual": "*"
}
],
"programFiles": [
"net/core/netpoll.c"
],
"defaultStatus": "affected"
}
]
}
],
"published": "2025-12-16T15:15:53.767",
"references": [
{
"url": "https://git.kernel.org/stable/c/49c8d2c1f94cc2f4d1a108530d7ba52614b874c2",
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
},
{
"url": "https://git.kernel.org/stable/c/4afd4ebbad52aa146838ec23082ba393e426a2bb",
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
},
{
"url": "https://git.kernel.org/stable/c/890472d6fbf062e6de7fdd56642cb305ab79d669",
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
},
{
"url": "https://git.kernel.org/stable/c/8e6a50edad11e3e1426e4c29e7aa6201f3468ac2",
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
},
{
"url": "https://git.kernel.org/stable/c/9a51b5ccd1c79afec1c03a4e1e6688da52597556",
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
},
{
"url": "https://git.kernel.org/stable/c/9b0bb18b4b9dc017c1825a2c5e763615e34a1593",
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
},
{
"url": "https://git.kernel.org/stable/c/c645693180a98606c430825223d2029315d85e9d",
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
},
{
"url": "https://git.kernel.org/stable/c/c79a6d9da29219616b118a3adce9a14cd30f9bd0",
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
}
],
"vulnStatus": "Deferred",
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\nnet: netpoll: fix incorrect refcount handling causing incorrect cleanup\n\ncommit efa95b01da18 (\"netpoll: fix use after free\") incorrectly\nignored the refcount and prematurely set dev->npinfo to NULL during\nnetpoll cleanup, leading to improper behavior and memory leaks.\n\nScenario causing lack of proper cleanup:\n\n1) A netpoll is associated with a NIC (e.g., eth0) and netdev->npinfo is\n allocated, and refcnt = 1\n - Keep in mind that npinfo is shared among all netpoll instances. In\n this case, there is just one.\n\n2) Another netpoll is also associated with the same NIC and\n npinfo->refcnt += 1.\n - Now dev->npinfo->refcnt = 2;\n - There is just one npinfo associated to the netdev.\n\n3) When the first netpolls goes to clean up:\n - The first cleanup succeeds and clears np->dev->npinfo, ignoring\n refcnt.\n - It basically calls `RCU_INIT_POINTER(np->dev->npinfo, NULL);`\n - Set dev->npinfo = NULL, without proper cleanup\n - No ->ndo_netpoll_cleanup() is either called\n\n4) Now the second target tries to clean up\n - The second cleanup fails because np->dev->npinfo is already NULL.\n * In this case, ops->ndo_netpoll_cleanup() was never called, and\n the skb pool is not cleaned as well (for the second netpoll\n instance)\n - This leaks npinfo and skbpool skbs, which is clearly reported by\n kmemleak.\n\nRevert commit efa95b01da18 (\"netpoll: fix use after free\") and adds\nclarifying comments emphasizing that npinfo cleanup should only happen\nonce the refcount reaches zero, ensuring stable and correct netpoll\nbehavior."
}
],
"lastModified": "2026-06-17T09:58:47.977",
"sourceIdentifier": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
}