In the Linux kernel, the following vulnerability has been resolved:
net: flow_dissector: use DEBUG_NET_WARN_ON_ONCE
The following splat is easy to reproduce upstream as well as in -stable kernels. Florian Westphal provided the following commit:
d1dab4f71d37 ("net: add and use __skb_get_hash_symmetric_net")
but this complementary fix has been also suggested by Willem de Bruijn and it can be easily backported to -stable kernel which consists in using DEBUG_NET_WARN_ON_ONCE instead to silence the following splat given __skb_get_hash() is used by the nftables tracing infrastructure to to identify packets in traces.
[69133.561393] ------------[ cut here ]------------ [69133.561404] WARNING: CPU: 0 PID: 43576 at net/core/flow_dissector.c:1104 __skb_flow_dissect+0x134f/ [...] [69133.561944] CPU: 0 PID: 43576 Comm: socat Not tainted 6.10.0-rc7+ #379 [69133.561959] RIP: 0010:__skb_flow_dissect+0x134f/0x2ad0 [69133.561970] Code: 83 f9 04 0f 84 b3 00 00 00 45 85 c9 0f 84 aa 00 00 00 41 83 f9 02 0f 84 81 fc ff ff 44 0f b7 b4 24 80 00 00 00 e9 8b f9 ff ff <0f> 0b e9 20 f3 ff ff 41 f6 c6 20 0f 84 e4 ef ff ff 48 8d 7b 12 e8 [69133.561979] RSP: 0018:ffffc90000006fc0 EFLAGS: 00010246 [69133.561988] RAX: 0000000000000000 RBX: ffffffff82f33e20 RCX: ffffffff81ab7e19 [69133.561994] RDX: dffffc0000000000 RSI: ffffc90000007388 RDI: ffff888103a1b418 [69133.562001] RBP: ffffc90000007310 R08: 0000000000000000 R09: 0000000000000000 [69133.562007] R10: ffffc90000007388 R11: ffffffff810cface R12: ffff888103a1b400 [69133.562013] R13: 0000000000000000 R14: ffffffff82f33e2a R15: ffffffff82f33e28 [69133.562020] FS: 00007f40f7131740(0000) GS:ffff888390800000(0000) knlGS:0000000000000000 [69133.562027] CS: 0010 DS: 0000 ES: 0000 CR0: 0000000080050033 [69133.562033] CR2: 00007f40f7346ee0 CR3: 000000015d200001 CR4: 00000000001706f0 [69133.562040] Call Trace: [69133.562044] <IRQ> [69133.562049] ? __warn+0x9f/0x1a0 [ 1211.841384] ? __skb_flow_dissect+0x107e/0x2860 [...] [ 1211.841496] ? bpf_flow_dissect+0x160/0x160 [ 1211.841753] __skb_get_hash+0x97/0x280 [ 1211.841765] ? __skb_get_hash_symmetric+0x230/0x230 [ 1211.841776] ? mod_find+0xbf/0xe0 [ 1211.841786] ? get_stack_info_noinstr+0x12/0xe0 [ 1211.841798] ? bpf_ksym_find+0x56/0xe0 [ 1211.841807] ? __rcu_read_unlock+0x2a/0x70 [ 1211.841819] nft_trace_init+0x1b9/0x1c0 [nf_tables] [ 1211.841895] ? nft_trace_notify+0x830/0x830 [nf_tables] [ 1211.841964] ? get_stack_info+0x2b/0x80 [ 1211.841975] ? nft_do_chain_arp+0x80/0x80 [nf_tables] [ 1211.842044] nft_do_chain+0x79c/0x850 [nf_tables]
CVSS Details
- CVSS 3.1 Base Score: 5.5
- CVSS 3.1 Vector: (CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Amazon_linux_2023 | — | Upgrade kernel-modules-extra-commonUpgrade kernel-develUpgrade kernel-debuginfo-common-aarch64Upgrade kernel-tools-develUpgrade kernelUpgrade kernel-libbpf-staticUpgrade python3-perfUpgrade perfUpgrade kernel-libbpfUpgrade kernel-headersUpgrade kernel-libbpf-develUpgrade kernel-debuginfoUpgrade kernel-tools-debuginfoUpgrade bpftoolUpgrade kernel-toolsUpgrade python3-perf-debuginfoUpgrade bpftool-debuginfoUpgrade kernel-debuginfo-common-x86_64Upgrade kernel-livepatch-6.1.106-116.188Upgrade kernel-modules-extraUpgrade perf-debuginfo | Oct 16, 2025 | Aug 17, 2024 |
| Debian | — | Upgrade linuxUpgrade linux-6.1 | Sep 2, 2024 | Aug 17, 2024 |
| Huawei Euleros 2_0_sp11 | — | Upgrade kernel-toolsUpgrade kernel-abi-stablelistsUpgrade kernel-tools-libsUpgrade bpftoolUpgrade kernelUpgrade python3-perf | Oct 9, 2024 | Aug 17, 2024 |
| Huawei Euleros 2_0_sp12 | — | Upgrade python3-perfUpgrade kernelUpgrade bpftoolUpgrade kernel-tools-libsUpgrade kernel-abi-stablelistsUpgrade kernel-tools | Nov 26, 2024 | Aug 17, 2024 |
| Redhat_linux | — | Upgrade kernelUpgrade kernel-rtNo solution exists | May 15, 2025 | Aug 17, 2024 |
| Ubuntu | — | Upgrade linux-image-kvmUpgrade linux-image-nvidia-hwe-22.04Upgrade linux-image-6.8.0-50-genericUpgrade linux-image-oem-24.04aUpgrade linux-image-lowlatency-64k-hwe-22.04Upgrade linux-image-generic-hwe-22.04Upgrade linux-image-awsUpgrade linux-image-virtual-hwe-22.04Upgrade linux-image-ibm-lts-24.04Upgrade linux-image-6.8.0-1019-nvidia-lowlatency-64kUpgrade linux-image-virtual-hwe-24.04Upgrade linux-image-6.8.0-50-lowlatencyUpgrade linux-image-oem-22.04bUpgrade linux-image-lowlatency-64k-hwe-24.04Upgrade linux-image-6.8.0-1017-oracleUpgrade linux-image-azure-fdeUpgrade linux-image-nvidia-64kUpgrade linux-image-ibm-classicUpgrade linux-image-oracle-64kUpgrade linux-image-6.8.0-1020-azure-fdeUpgrade linux-image-6.8.0-1019-nvidia-lowlatencyUpgrade linux-image-oem-22.04cUpgrade linux-image-gcpUpgrade linux-image-oem-22.04dUpgrade linux-image-generic-hwe-24.04Upgrade linux-image-azureUpgrade linux-image-raspiUpgrade linux-image-6.8.0-50-lowlatency-64kUpgrade linux-image-6.8.0-1019-nvidiaUpgrade linux-image-lowlatency-hwe-24.04Upgrade linux-image-generic-64kUpgrade linux-image-genericUpgrade linux-image-6.8.0-1002-gkeopUpgrade linux-image-6.8.0-1017-ibmUpgrade linux-image-6.8.0-1019-gcpUpgrade linux-image-6.8.0-50-generic-64kUpgrade linux-image-virtualUpgrade linux-image-oem-22.04aUpgrade linux-image-generic-lpaeUpgrade linux-image-gkeop-6.8Upgrade linux-image-lowlatencyUpgrade linux-image-6.8.0-1017-oracle-64kUpgrade linux-image-nvidia-64k-hwe-22.04Upgrade linux-image-nvidia-6.8Upgrade linux-image-6.8.0-1016-raspiUpgrade linux-image-gkeUpgrade linux-image-nvidiaUpgrade linux-image-6.8.0-1015-gkeUpgrade linux-image-nvidia-lowlatency-64kUpgrade linux-image-lowlatency-64kUpgrade linux-image-6.8.0-1018-oemUpgrade linux-image-6.8.0-1020-awsUpgrade linux-image-oem-22.04Upgrade linux-image-ibmUpgrade linux-image-gkeopUpgrade linux-image-oem-24.04Upgrade linux-image-generic-64k-hwe-22.04Upgrade linux-image-nvidia-64k-6.8Upgrade linux-image-6.8.0-1019-nvidia-64kUpgrade linux-image-generic-64k-hwe-24.04Upgrade linux-image-nvidia-lowlatencyUpgrade linux-image-oracleUpgrade linux-image-6.8.0-1020-azureUpgrade linux-image-lowlatency-hwe-22.04 | Dec 13, 2024 | Aug 17, 2024 |
| Vmware Photon_os | — | Use 'tdnf update' to upgrade all packages to the latest version. | Jan 20, 2025 | Aug 17, 2024 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub