{"id":"CVE-2025-71097","title":"ipv4: Fix reference count leak when using error routes with nexthop objects","summary":"In the Linux kernel, the following vulnerability has been resolved:\n\nipv4: Fix reference count leak when using error routes with nexthop objects\n\nWhen a nexthop object is deleted, it is marked as dead and then\nfib_table_flush() is called…","severity":"none","vendor":"Linux","product":"Linux","affected":["Linux >= 493ced1ac47c48bb86d9d4e8e87df8592be85a0e < 5de7ad7e18356e39e8fbf7edd185a5faaf4f385a","Linux >= 493ced1ac47c48bb86d9d4e8e87df8592be85a0e < 33ff5c207c873215e54e6176624ed57423cb7dea","Linux >= 493ced1ac47c48bb86d9d4e8e87df8592be85a0e < 30386e090c49e803c0616a7147e43409c32a2b0e","Linux >= 493ced1ac47c48bb86d9d4e8e87df8592be85a0e < 5979338c83012110ccd45cae6517591770bfe536","Linux >= 493ced1ac47c48bb86d9d4e8e87df8592be85a0e < ee4183501ea556dca31f5ffd8690aa9fd25b609f","Linux >= 493ced1ac47c48bb86d9d4e8e87df8592be85a0e < e3fc381320d04e4a74311e576a86cac49a16fc43","Linux >= 493ced1ac47c48bb86d9d4e8e87df8592be85a0e < ac782f4e3bfcde145b8a7f8af31d9422d94d172a","Linux 5.3"],"ssvc":{"exploitation":"none","automatable":"no","technicalImpact":"partial","timestamp":"2026-06-10T20:40:27.713433Z"},"published":"2026-01-13","updated":"2026-09-08","sourceUpdated":"2026-09-08T08:43:50.602Z","source":"CVEORG","sourceUrl":"https://www.cve.org/CVERecord?id=CVE-2025-71097","references":[{"url":"https://git.kernel.org/stable/c/5de7ad7e18356e39e8fbf7edd185a5faaf4f385a"},{"url":"https://git.kernel.org/stable/c/33ff5c207c873215e54e6176624ed57423cb7dea"},{"url":"https://git.kernel.org/stable/c/30386e090c49e803c0616a7147e43409c32a2b0e"},{"url":"https://git.kernel.org/stable/c/5979338c83012110ccd45cae6517591770bfe536"},{"url":"https://git.kernel.org/stable/c/ee4183501ea556dca31f5ffd8690aa9fd25b609f"},{"url":"https://git.kernel.org/stable/c/e3fc381320d04e4a74311e576a86cac49a16fc43"},{"url":"https://git.kernel.org/stable/c/ac782f4e3bfcde145b8a7f8af31d9422d94d172a"}],"tags":["cve.org"],"epss":0.00134,"epssPercentile":0.0325,"ingestedAt":"2026-09-08T15:33:26.995Z","slug":"CVE-2025-71097","body":"## Overview\n\nIn the Linux kernel, the following vulnerability has been resolved:\n\nipv4: Fix reference count leak when using error routes with nexthop objects\n\nWhen a nexthop object is deleted, it is marked as dead and then\nfib_table_flush() is called to flush all the routes that are using the\ndead nexthop.\n\nThe current logic in fib_table_flush() is to only flush error routes\n(e.g., blackhole) when it is called as part of network namespace\ndismantle (i.e., with flush_all=true). Therefore, error routes are not\nflushed when their nexthop object is deleted:\n\n # ip link add name dummy1 up type dummy\n # ip nexthop add id 1 dev dummy1\n # ip route add 198.51.100.1/32 nhid 1\n # ip route add blackhole 198.51.100.2/32 nhid 1\n # ip nexthop del id 1\n # ip route show\n blackhole 198.51.100.2 nhid 1 dev dummy1\n\nAs such, they keep holding a reference on the nexthop object which in\nturn holds a reference on the nexthop device, resulting in a reference\ncount leak:\n\n # ip link del dev dummy1\n [   70.516258] unregister_netdevice: waiting for dummy1 to become free. Usage count = 2\n\nFix by flushing error routes when their nexthop is marked as dead.\n\nIPv6 does not suffer from this problem.\n\n## Affected\n\n- `Linux >= 493ced1ac47c48bb86d9d4e8e87df8592be85a0e < 5de7ad7e18356e39e8fbf7edd185a5faaf4f385a`\n- `Linux >= 493ced1ac47c48bb86d9d4e8e87df8592be85a0e < 33ff5c207c873215e54e6176624ed57423cb7dea`\n- `Linux >= 493ced1ac47c48bb86d9d4e8e87df8592be85a0e < 30386e090c49e803c0616a7147e43409c32a2b0e`\n- `Linux >= 493ced1ac47c48bb86d9d4e8e87df8592be85a0e < 5979338c83012110ccd45cae6517591770bfe536`\n- `Linux >= 493ced1ac47c48bb86d9d4e8e87df8592be85a0e < ee4183501ea556dca31f5ffd8690aa9fd25b609f`\n- `Linux >= 493ced1ac47c48bb86d9d4e8e87df8592be85a0e < e3fc381320d04e4a74311e576a86cac49a16fc43`\n- `Linux >= 493ced1ac47c48bb86d9d4e8e87df8592be85a0e < ac782f4e3bfcde145b8a7f8af31d9422d94d172a`\n- `Linux 5.3`\n\n## Remediation\n\nRefer to the linked advisories for vendor-supplied fixes and affected version ranges.","depth":"sunlit","depthScore":3,"depthScoreParts":{"impact":2.8,"likelihood":0,"exploitation":0,"ransomware":0},"changes":[]}