CVE-2025-68768: inet: frags: flush pending skbs in fqdir_pre_exit()
In the Linux kernel, the following vulnerability has been resolved:
inet: frags: flush pending skbs in fqdirpreexit()
We have been seeing occasional deadlocks on pernetopsrwsem since September in NIPA. The stuck task was usually modprobe (often loading a driver like ipvlan), trying to take the lock as a Writer. lockdep does not track readers for rwsems so the read wasn't obvious from the reports.
On closer inspection the Reader holding the lock was conntrack looping forever in nfconntrackcleanupnetlist(). Based on past experience with occasional NIPA crashes I looked thru the tests which run before the crash and noticed that the crash follows ipdefrag.sh. An immediate red flag. Scouring thru (de)fragmentation queues reveals skbs sitting around, holding conntrack references.
The problem is that since conntrack depends on nfdefragipv6, nfdefragipv6 will load first. Since nfdefragipv6 loads first its netns exit hooks run after conntrack's netns exit hook.
Flush all fragment queue SKBs during fqdirpreexit() to release conntrack references before conntrack cleanup runs. Also flush the queues in timer expiry handlers when they discover fqdir->dead is set, in case packet sneaks in while we're running the preexit flush.
The commit under Fixes is not exactly the culprit, but I think previously the timer firing would eventually unblock the spinning conntrack.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 6.6.143.1-1
Event History
Frequently Asked Questions
What is the severity of CVE-2025-68768?
CVE-2025-68768 is categorized as a moderate severity vulnerability due to the potential for deadlocks in the Linux kernel.
How do I fix CVE-2025-68768?
To fix CVE-2025-68768, ensure you update your Linux kernel to the latest stable version that includes the patch addressing this vulnerability.
What does CVE-2025-68768 affect?
CVE-2025-68768 affects Linux kernel versions prior to the patch, specifically related to the handling of pending socket buffers.
What is the impact of CVE-2025-68768?
The impact of CVE-2025-68768 can lead to system deadlocks, potentially disrupting normal operations and affecting service availability.
When was CVE-2025-68768 discovered?
CVE-2025-68768 was discovered in September 2025 and was associated with issues related to deadlocks in the Linux kernel.