# CVE-2025-71097

## Summary

- **CVE ID:** CVE-2025-71097
- **Severity:** MEDIUM
- **CVSS Score:** 5.5 (CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H)
- **CWE:** N/A
- **Published:** Jan 13, 2026
- **Last Modified:** Sep 8, 2026

## Description

In the Linux kernel, the following vulnerability has been resolved:

ipv4: Fix reference count leak when using error routes with nexthop objects

When a nexthop object is deleted, it is marked as dead and then
fib_table_flush() is called to flush all the routes that are using the
dead nexthop.

The current logic in fib_table_flush() is to only flush error routes
(e.g., blackhole) when it is called as part of network namespace
dismantle (i.e., with flush_all=true). Therefore, error routes are not
flushed when their nexthop object is deleted:

 # ip link add name dummy1 up type dummy
 # ip nexthop add id 1 dev dummy1
 # ip route add 198.51.100.1/32 nhid 1
 # ip route add blackhole 198.51.100.2/32 nhid 1
 # ip nexthop del id 1
 # ip route show
 blackhole 198.51.100.2 nhid 1 dev dummy1

As such, they keep holding a reference on the nexthop object which in
turn holds a reference on the nexthop device, resulting in a reference
count leak:

 # ip link del dev dummy1
 [   70.516258] unregister_netdevice: waiting for dummy1 to become free. Usage count = 2

Fix by flushing error routes when their nexthop is marked as dead.

IPv6 does not suffer from this problem.

## Affected Products

- Linux — Linux (493ced1ac47c48bb86d9d4e8e87df8592be85a0e)
- Linux — Linux (5.3)
- Linux — Linux (0)
- Linux — Linux (5.10.248)
- Linux — Linux (5.15.198)
- Linux — Linux (6.1.160)
- Linux — Linux (6.6.120)
- Linux — Linux (6.12.64)
- Linux — Linux (6.18.4)
- Linux — Linux (6.19)

## References

- [CNA](https://git.kernel.org/stable/c/5de7ad7e18356e39e8fbf7edd185a5faaf4f385a)
- [CNA](https://git.kernel.org/stable/c/33ff5c207c873215e54e6176624ed57423cb7dea)
- [CNA](https://git.kernel.org/stable/c/30386e090c49e803c0616a7147e43409c32a2b0e)
- [CNA](https://git.kernel.org/stable/c/5979338c83012110ccd45cae6517591770bfe536)
- [CNA](https://git.kernel.org/stable/c/ee4183501ea556dca31f5ffd8690aa9fd25b609f)
- [CNA](https://git.kernel.org/stable/c/e3fc381320d04e4a74311e576a86cac49a16fc43)
- [CNA](https://git.kernel.org/stable/c/ac782f4e3bfcde145b8a7f8af31d9422d94d172a)
- [siemens-SADP](https://cert-portal.siemens.com/productcert/html/ssa-019113.html)

## Exploitation Prediction (EPSS)

- **EPSS Score:** 0.13%
- **EPSS Percentile:** 3.3

---
_Exported from OnDuty AI Vulnerability Intelligence on 2026-09-18._