CVE-2025-38678 is a flaw in the Linux kernel netfilter nf_tables subsystem affecting chain and flowtable update handling. During an update transaction, it was possible to include the same network device more than once in the same batch. The netdev event handling path removed only the first matching device, which left the hook associated with the duplicated device in an inconsistent unregistered state. This state mismatch could later trigger a kernel WARNING during hook unregistration in the netfilter core. The fix rejects transaction batches containing duplicate devices and returns EEXIST instead of allowing the inconsistent update to proceed.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
1 valid exploit after Mallory filtered fakes, detection scripts, and README-only repos.
This repository contains a proof-of-concept (POC) exploit for CVE-2025-38678, targeting the Linux kernel's nftables subsystem. The main file, 'poc.c', is a C program that demonstrates the exploit by setting up user and network namespaces, creating virtual Ethernet (veth) devices, and crafting netlink messages to interact with the kernel's netfilter/nftables interfaces. The code manipulates kernel networking structures and likely triggers a vulnerability in the handling of nftables flowtables. The exploit is local, requiring execution on a Linux system with appropriate privileges to create namespaces and network devices. No remote or network endpoints are targeted; all actions are performed via local kernel interfaces and /proc files. The repository is structured simply, with a single code file, a README referencing the CVE, and a license file. This POC is intended for research and demonstration purposes, not as a weaponized exploit.
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
8 sources tracked across advisories and community write-ups. News coverage will land here when it surfaces.
No news coverage yet. Advisories and community discussion only.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.