CVE-2025-71146
Estado: ModificadaMedia (5.5)—
In the Linux kernel, the following vulnerability has been resolved:
netfilter: nf_conncount: fix leaked ct in error paths
There are some situations where ct might be leaked as error paths are skipping the refcounted check and return immediately. In order to solve it make sure that the check is always called.
CVSS
- Versión: 3.1
- Vector: CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
- Puntuación base: 5.5
Probabilidad de explotación (EPSS)
- Probabilidad de explotación en los próximos 30 días: 0.28%
- Percentil entre todas las CVEs puntuadas: 19
- Fecha de la puntuación: 6/10/2026
EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).
Tecnologías afectadas (1)
CWE
- CWE-401
Referencias
- https://git.kernel.org/stable/c/08fa37f4c8c59c294e9c18fea2d083ee94074e5a
- https://git.kernel.org/stable/c/0b88be7211d21a0d68bb1e56dc805944e3654d6f
- https://git.kernel.org/stable/c/2e2a720766886190a6d35c116794693aabd332b6
- https://git.kernel.org/stable/c/325eb61bb30790ea27782203a17b007ce1754a67
- https://git.kernel.org/stable/c/4bd2b89f4028f250dd1c1625eb3da1979b04a5e8
- https://git.kernel.org/stable/c/e1ac8dce3a893641bef224ad057932f142b8a36f
- https://git.kernel.org/stable/c/f381a33f34dda9e4023e38ba68c943bca83245e9
JSON original (NVD)
Mostrar
{
"id": "CVE-2025-71146",
"cveTags": [],
"metrics": {
"cvssMetricV31": [
{
"type": "Secondary",
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"cvssData": {
"scope": "UNCHANGED",
"version": "3.1",
"baseScore": 7.5,
"attackVector": "NETWORK",
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
"integrityImpact": "NONE",
"userInteraction": "NONE",
"attackComplexity": "LOW",
"availabilityImpact": "HIGH",
"privilegesRequired": "NONE",
"confidentialityImpact": "NONE"
},
"impactScore": 3.6,
"exploitabilityScore": 3.9
},
{
"type": "Primary",
"source": "nvd@nist.gov",
"cvssData": {
"scope": "UNCHANGED",
"version": "3.1",
"baseScore": 5.5,
"attackVector": "LOCAL",
"baseSeverity": "MEDIUM",
"vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H",
"integrityImpact": "NONE",
"userInteraction": "NONE",
"attackComplexity": "LOW",
"availabilityImpact": "HIGH",
"privilegesRequired": "LOW",
"confidentialityImpact": "NONE"
},
"impactScore": 3.6,
"exploitabilityScore": 1.8
}
]
},
"affected": [
{
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"affectedData": [
{
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"product": "Linux",
"versions": [
{
"status": "affected",
"version": "6e86f0eca857ee42787e30e9ec0b726aebfcae0a",
"lessThan": "08fa37f4c8c59c294e9c18fea2d083ee94074e5a",
"versionType": "git"
},
{
"status": "affected",
"version": "b160895d6bc9690459b16ef87799c9bd456af3ec",
"lessThan": "e1ac8dce3a893641bef224ad057932f142b8a36f",
"versionType": "git"
},
{
"status": "affected",
"version": "8d5a2c94c24dcc226863a7c2b5034750370c2189",
"lessThan": "f381a33f34dda9e4023e38ba68c943bca83245e9",
"versionType": "git"
},
{
"status": "affected",
"version": "da9f247fb5efcd5a2730cdc989291b383c439e10",
"lessThan": "325eb61bb30790ea27782203a17b007ce1754a67",
"versionType": "git"
},
{
"status": "affected",
"version": "3558faee8aace3541189c3a2ca45c7e85e144b44",
"lessThan": "0b88be7211d21a0d68bb1e56dc805944e3654d6f",
"versionType": "git"
},
{
"status": "affected",
"version": "f6904ed15ed1a188543057e3cb0d02daa80edfc9",
"lessThan": "4bd2b89f4028f250dd1c1625eb3da1979b04a5e8",
"versionType": "git"
},
{
"status": "affected",
"version": "be102eb6a0e7c03db00e50540622f4e43b2d2844",
"lessThan": "2e2a720766886190a6d35c116794693aabd332b6",
"versionType": "git"
},
{
"status": "affected",
"version": "8c2da7330214ce30f8333d1799a27ed0a9418f07",
"versionType": "git"
},
{
"status": "affected",
"version": "6.17.13",
"lessThan": "6.18",
"versionType": "semver"
}
],
"programFiles": [
"net/netfilter/nf_conncount.c"
],
"defaultStatus": "unaffected"
},
{
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"product": "Linux",
"versions": [
{
"status": "affected",
"version": "6.12.63",
"lessThan": "6.12.64",
"versionType": "semver"
},
{
"status": "affected",
"version": "6.18.2",
"lessThan": "6.18.3",
"versionType": "semver"
}
],
"programFiles": [
"net/netfilter/nf_conncount.c"
],
"defaultStatus": "unaffected"
}
]
}
],
"published": "2026-01-23T15:16:05.230",
"references": [
{
"url": "https://git.kernel.org/stable/c/08fa37f4c8c59c294e9c18fea2d083ee94074e5a",
"tags": [
"Patch"
],
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
},
{
"url": "https://git.kernel.org/stable/c/0b88be7211d21a0d68bb1e56dc805944e3654d6f",
"tags": [
"Patch"
],
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
},
{
"url": "https://git.kernel.org/stable/c/2e2a720766886190a6d35c116794693aabd332b6",
"tags": [
"Patch"
],
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
},
{
"url": "https://git.kernel.org/stable/c/325eb61bb30790ea27782203a17b007ce1754a67",
"tags": [
"Patch"
],
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
},
{
"url": "https://git.kernel.org/stable/c/4bd2b89f4028f250dd1c1625eb3da1979b04a5e8",
"tags": [
"Patch"
],
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
},
{
"url": "https://git.kernel.org/stable/c/e1ac8dce3a893641bef224ad057932f142b8a36f",
"tags": [
"Patch"
],
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
},
{
"url": "https://git.kernel.org/stable/c/f381a33f34dda9e4023e38ba68c943bca83245e9",
"tags": [
"Patch"
],
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
}
],
"vulnStatus": "Modified",
"weaknesses": [
{
"type": "Primary",
"source": "nvd@nist.gov",
"description": [
{
"lang": "en",
"value": "CWE-401"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\nnetfilter: nf_conncount: fix leaked ct in error paths\n\nThere are some situations where ct might be leaked as error paths are\nskipping the refcounted check and return immediately. In order to solve\nit make sure that the check is always called."
},
{
"lang": "es",
"value": "En el kernel de Linux, la siguiente vulnerabilidad ha sido resuelta:\n\nnetfilter: nf_conncount: corrección de 'ct' filtrado en rutas de error\n\nExisten algunas situaciones en las que 'ct' podría filtrarse, ya que las rutas de error están omitiendo la verificación de conteo de referencias y retornan inmediatamente. Para resolverlo, hay que asegurarse de que la verificación siempre sea llamada."
}
],
"lastModified": "2026-07-30T06:24:54.520",
"configurations": [
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "7C298528-1754-41BD-B4E9-84A37AB7BA32",
"versionEndExcluding": "6.18",
"versionStartIncluding": "6.17.13"
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:6.12.63:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "7984A97B-8D26-49DE-B98A-80F987DC6ECE"
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:6.18.2:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "3F3959F8-92E0-4D2C-B5DA-B3BB4BE80113"
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:6.19:rc1:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "17B67AA7-40D6-4AFA-8459-F200F3D7CFD1"
}
],
"operator": "OR"
}
]
}
],
"sourceIdentifier": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
}