In the Linux kernel, the following vulnerability has been resolved:
netfilter: nft_set_pipapo: clamp maximum map bucket size to INT_MAX
Otherwise, it is possible to hit WARN_ON_ONCE in __kvmalloc_node_noprof()
when resizing hashtable because __GFP_NOWARN is unset.
Similar to:
b541ba7d1f5a ("netfilter: conntrack: clamp maximum hashtable size to INT_MAX")
Metrics
Affected Vendors & Products
References
History
Sat, 05 Jul 2025 00:30:00 +0000
Type | Values Removed | Values Added |
---|---|---|
References |
| |
Metrics |
threat_severity
|
cvssV3_1
|
Fri, 04 Jul 2025 13:45:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | In the Linux kernel, the following vulnerability has been resolved: netfilter: nft_set_pipapo: clamp maximum map bucket size to INT_MAX Otherwise, it is possible to hit WARN_ON_ONCE in __kvmalloc_node_noprof() when resizing hashtable because __GFP_NOWARN is unset. Similar to: b541ba7d1f5a ("netfilter: conntrack: clamp maximum hashtable size to INT_MAX") | |
Title | netfilter: nft_set_pipapo: clamp maximum map bucket size to INT_MAX | |
References |
|

Status: PUBLISHED
Assigner: Linux
Published: 2025-07-04T13:37:22.732Z
Updated: 2025-07-28T04:14:56.757Z
Reserved: 2025-04-16T04:51:23.993Z
Link: CVE-2025-38201

No data.

Status : Awaiting Analysis
Published: 2025-07-04T14:15:28.000
Modified: 2025-07-08T16:18:53.607
Link: CVE-2025-38201
