Kernel panic in __nf_ct_delete_from_lists

Solution Verified - Updated -

Issue

  • What is CVE-2025-38472?
  • system repeated reboot
  • Kernel crash [exception RIP: __nf_ct_delete_from_lists+0xac]
  • Kernel crash [exception RIP: __nf_ct_delete_from_lists+172]
  • vmcore with panic backtrace:
    [exception RIP: __nf_ct_delete_from_lists+0xac]

 #7 [ff6479a1995dca10] nf_ct_delete at ffffffffc14c0a51 [nf_conntrack]
 #8 [ff6479a1995dca40] nf_ct_gc_expired at ffffffffc14c1049 [nf_conntrack]
 #9 [ff6479a1995dca50] early_drop at ffffffffc14c14b3 [nf_conntrack]
#10 [ff6479a1995dca90] __nf_conntrack_alloc at ffffffffc14c16c4 [nf_conntrack]
#11 [ff6479a1995dcad0] init_conntrack.constprop.0 at ffffffffc14c1b0b [nf_conntrack]
#12 [ff6479a1995dcb40] resolve_normal_ct at ffffffffc14c2b10 [nf_conntrack]
#13 [ff6479a1995dcbb8] nf_conntrack_in at ffffffffc14c2cdf [nf_conntrack]
#14 [ff6479a1995dcc08] nf_hook_slow at ffffffffb2b2ca4c
#15 [ff6479a1995dcc38] nf_hook_slow_list at ffffffffb2b2cba1
#16 [ff6479a1995dcc90] ip_sublist_rcv at ffffffffb2b3c333
#17 [ff6479a1995dcd10] ip_list_rcv at ffffffffb2b3c775
#18 [ff6479a1995dcd70] __netif_receive_skb_list_core at ffffffffb2a8828f
#19 [ff6479a1995dcdf0] netif_receive_skb_list_internal at ffffffffb2a88976
#20 [ff6479a1995dce58] napi_complete_done at ffffffffb2a88c2e
#21 [ff6479a1995dce80] ice_napi_poll at ffffffffc0b47cb8 [ice]
#22 [ff6479a1995dcee0] __napi_poll at ffffffffb2a88e19
#23 [ff6479a1995dcf08] net_rx_action at ffffffffb2a8947c
#24 [ff6479a1995dcf88] handle_softirqs at ffffffffb2118a8e
#25 [ff6479a1995dcfe0] __irq_exit_rcu at ffffffffb2118d23
#26 [ff6479a1995dcff0] common_interrupt at ffffffffb2d21090
--- <IRQ stack> ---

Environment

  • Red Hat Enterprise Linux 10.1 and earlier
  • Red Hat Enterprise Linux 9.6 and earlier
  • Firewall (iptables, nftables, firewalld) with connection tracking
    • Firewall rules matching on ct state
    • nf_conntrack kernel module loaded

Subscriber exclusive content

A Red Hat subscription provides unlimited access to our knowledgebase, tools, and much more.

Current Customers and Partners

Log in for full access

Log In

New to Red Hat?

Learn more about Red Hat subscriptions

Using a Red Hat product through a public cloud?

How to access this content