CVE-2025-22057: net: decrease cached dst counters in dst_release

Published Apr 16, 2025
·
Updated

In the Linux kernel, the following vulnerability has been resolved:

net: decrease cached dst counters in dstrelease

Upstream fix ac888d58869b ("net: do not delay dstentriesadd() in dstrelease()") moved decrementing the dst count from dstdestroy to dstrelease to avoid accessing already freed data in case of netns dismantle. However in case CONFIGDSTCACHE is enabled and OvS+tunnels are used, this fix is incomplete as the same issue will be seen for cached dsts:

Unable to handle kernel paging request at virtual address ffff5aabf6b5c000 Call trace: percpucounteraddbatch+0x3c/0x160 (P) dstrelease+0xec/0x108 dstcachedestroy+0x68/0xd8 dstdestroy+0x13c/0x168 dstdestroyrcu+0x1c/0xb0 rcudobatch+0x18c/0x7d0 rcucore+0x174/0x378 rcucoresi+0x18/0x30

Fix this by invalidating the cache, and thus decrementing cached dst counters, in dstrelease too.

Affected Software

8 affected componentsFixes available
Linux Kernel
Microsoft cbl2 kernel 5.15.186.1-1
Linux Linux kernel>=4.6<6.6.87
Linux Linux kernel>=6.7<6.12.23
Linux Linux kernel>=6.13<6.13.11
Linux Linux kernel>=6.14<6.14.2
Microsoft azl3 kernel 6.6.92.2-1<6.6.92.2-1
6.6.92.2-1
Microsoft azl3 kernel 6.6.85.1-4<6.6.92.2-1
6.6.92.2-1

Remediation

Recommended actions to resolve this vulnerability, in priority order.

  1. Upgrade

    Upgrade to a fixed release to a version that resolves this vulnerability.

    Fixed in 6.6.92.2-1
  2. Upgrade

    Upgrade to a fixed release to a version that resolves this vulnerability.

    Patch ac888d58869b
  3. Operational

    Invalidate the cache to decrement cached dst entries (as described: “Fix this by invalidating the cache, and thus decrementing cached dst”).

  4. Operational

    Ensure CONFIG_DST_CACHE is disabled or apply the upstream fix behavior so that cached dst counters are decreased in dst_release as in the statement “net: decrease cached dst counters in dst_release” (to address the incomplete fix when CONFIG_DST_CACHE is enabled with OvS+tunnels).

Event History

Apr 16, 2025
CVE Published
via MITRE·02:12 PM
Data Sourced
via MITRE·02:12 PM
DescriptionSeverity
Data Sourced
via NVD·03:15 PM
RemedyDescriptionSeverityAffected Software
Jul 11, 2025
Data Sourced
via Microsoft·12:00 AM
DescriptionSeverityWeaknessAffected Software
Updated
via Microsoft·07:00 AM
SeverityAffected Software
Updated
via Microsoft·07:00 AM
DescriptionSeverity

Frequently Asked Questions

1

Which systems are most likely to trigger this issue?

The described crash condition requires CONFIG_DST_CACHE to be enabled and Open vSwitch used with tunnels. Systems not using that combination are not identified in the provided data as triggering the cached-dst path.

2

What is the likely impact if the issue is triggered?

The report shows a kernel paging request in the dst release and destruction path. The CVSS vector assigns high availability impact, indicating that exploitation can cause a denial of service.

3

What access does an attacker need?

The supplied CVSS vector rates attack vector as local and privileges required as low, with no user interaction required. The data does not describe a specific attack technique or required local privilege.

4

Which listed kernel builds should be reviewed for remediation status?

Review Linux kernel deployments and the specifically listed Microsoft builds: cbl2 kernel 5.15.186.1-1, azl3 kernel 6.6.92.2-1, and azl3 kernel 6.6.85.1-4. The provided references identify stable-kernel fixes, but the data does not map individual fixed versions to each listed product build.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203