CVE-2025-22021
Linux Kernel vulnerability analysis and mitigation

Overview

A vulnerability in the Linux kernel's netfilter subsystem was discovered and assigned CVE-2025-22021. The issue was disclosed on April 16, 2025, affecting the IPv6 SNAT (Source Network Address Translation) functionality. The vulnerability specifically impacts the nf_sk_lookup_slow_v6 function, which lacks proper conntrack lookup functionality compared to its IPv4 counterpart (NVD).

Technical details

The vulnerability stems from a missing conntrack lookup in the nf_sk_lookup_slow_v6 function, which is responsible for handling IPv6 SNAT packets. While the IPv4 version (nf_sk_lookup_slow_v4) correctly performs conntrack lookup to restore the original 5-tuple in SNAT cases, the IPv6 implementation lacks this functionality. This causes xt_socket to fail when matching on the socket for SNATed packets. The issue particularly affects Kubernetes clusters where IPv6 SNAT is used for pod-to-world packets, as pods' addresses in the fd00::/8 ULA subnet need translation to the node's external address (NVD, Red Hat).

Impact

The vulnerability affects Kubernetes environments using Cilium for network policy enforcement. Specifically, when Cilium uses Envoy to enforce L7 policies with transparent sockets, the iptables prerouting rules that match on -m socket --transparent and redirect packets to localhost fail to match SNATed IPv6 packets due to the missing conntrack lookup (NVD).

Mitigation and workarounds

Red Hat has marked this vulnerability as having 'Moderate' impact with a CVSS v3 score of 5.5. For Red Hat Enterprise Linux 9, the fix has been deferred, while versions 6 and 7 are not affected. The vulnerability has been resolved in the Linux kernel by adding the same conntrack lookup logic to nf_sk_lookup_slow_v6 that exists in the IPv4 implementation (Red Hat).

Additional resources


SourceThis report was generated using AI

Related Linux Kernel vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2025-71142N/AN/A
  • Linux KernelLinux Kernel
  • kernel-64k-debug-devel-matched
NoNoJan 14, 2026
CVE-2025-71137N/AN/A
  • Linux KernelLinux Kernel
  • linux-gcp
NoYesJan 14, 2026
CVE-2025-71135N/AN/A
  • Linux KernelLinux Kernel
  • kernel-debug-core
NoNoJan 14, 2026
CVE-2025-71134N/AN/A
  • Linux KernelLinux Kernel
  • kernel-uki-virt
NoNoJan 14, 2026
CVE-2025-71133N/AN/A
  • Linux KernelLinux Kernel
  • kernel-modules-extra
NoYesJan 14, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management