[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"repo-stars":3,"vuln-DEBIAN-CVE-2025-39894":6},{"stargazers_count":4,"fetched_at":5},8,"2026-09-19T04:32:17.889Z",{"id":7,"descriptions":8,"cisa":9,"weaknesses":10,"exploits":11,"aliases":12,"duplicate_of":9,"upstream":13,"downstream":16,"duplicates":19,"related":20,"reserved_at":9,"published_at":21,"modified_at":22,"state":9,"summary":23,"references_raw":25,"kevs":32,"epss":9,"epss_history":33,"metrics":34,"affected":41},"DEBIAN-CVE-2025-39894","In the Linux kernel, the following vulnerability has been resolved:  netfilter: br_netfilter: do not check confirmed bit in br_nf_local_in() after confirm  When send a broadcast packet to a tap device, which was added to a bridge, br_nf_local_in() is called to confirm the conntrack. If another conntrack with the same hash value is added to the hash table, which can be triggered by a normal packet to a non-bridge device, the below warning may happen.    ------------[ cut here ]------------   WARNING: CPU: 1 PID: 96 at net/bridge/br_netfilter_hooks.c:632 br_nf_local_in+0x168/0x200   CPU: 1 UID: 0 PID: 96 Comm: tap_send Not tainted 6.17.0-rc2-dirty #44 PREEMPT(voluntary)   RIP: 0010:br_nf_local_in+0x168/0x200   Call Trace:    \u003CTASK>    nf_hook_slow+0x3e/0xf0    br_pass_frame_up+0x103/0x180    br_handle_frame_finish+0x2de/0x5b0    br_nf_hook_thresh+0xc0/0x120    br_nf_pre_routing_finish+0x168/0x3a0    br_nf_pre_routing+0x237/0x5e0    br_handle_frame+0x1ec/0x3c0    __netif_receive_skb_core+0x225/0x1210    __netif_receive_skb_one_core+0x37/0xa0    netif_receive_skb+0x36/0x160    tun_get_user+0xa54/0x10c0    tun_chr_write_iter+0x65/0xb0    vfs_write+0x305/0x410    ksys_write+0x60/0xd0    do_syscall_64+0xa4/0x260    entry_SYSCALL_64_after_hwframe+0x77/0x7f    \u003C/TASK>   ---[ end trace 0000000000000000 ]---  To solve the hash conflict, nf_ct_resolve_clash() try to merge the conntracks, and update skb->_nfct. However, br_nf_local_in() still use the old ct from local variable 'nfct' after confirm(), which leads to this warning.  If confirm() does not insert the conntrack entry and return NF_DROP, the warning may also occur. There is no need to reserve the WARN_ON_ONCE, just remove it.",null,[],[],[],[14],{"_key":15},"CVE-2025-39894",[17],{"_key":18},"DLA-4328-1",[],[],"2025-10-01T08:15:31.987Z","2026-06-15T19:05:48.482863054Z",{"cisa_kev":24,"cisa_ransomware":24,"cisa_vendor":9,"epss_severity":9,"epss_score":9,"severity":9,"severity_score":9,"severity_version":9,"severity_source":9,"severity_vector":9,"severity_status":9},false,[26],{"url":27,"sources":28,"tags":30},"https://security-tracker.debian.org/tracker/CVE-2025-39894",[29],"osv_debian",[31],"Advisory",[],[],[35],{"source":29,"cvss_v2_0":9,"cvss_v3_0":9,"cvss_v3_1":36,"cvss_v4_0":9},{"baseScore":37,"baseSeverity":9,"vectorString":38,"impactScore":39,"exploitabilityScore":40},5.5,"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H",6,4.6,[42,60],{"ecosystem":43,"name":44,"vendor":45,"product":44,"cpe_part":9,"purl_type":46,"purl_namespace":45,"purl_name":44,"source":9,"versions":47},"Debian","linux","debian","deb",[48,54,57],{"version":49,"is_range":50,"range_type":51,"version_start":9,"version_start_type":9,"version_end":52,"version_end_type":53,"fixed_in":9},"lt6_1_153_1",true,"ecosystem","6.1.153-1","excluding",{"version":55,"is_range":50,"range_type":51,"version_start":9,"version_start_type":9,"version_end":56,"version_end_type":53,"fixed_in":9},"lt6_12_48_1","6.12.48-1",{"version":58,"is_range":50,"range_type":51,"version_start":9,"version_start_type":9,"version_end":59,"version_end_type":53,"fixed_in":9},"lt6_16_6_1","6.16.6-1",{"ecosystem":43,"name":61,"vendor":45,"product":61,"cpe_part":9,"purl_type":46,"purl_namespace":45,"purl_name":61,"source":9,"versions":62},"linux-6.1",[63],{"version":64,"is_range":50,"range_type":51,"version_start":9,"version_start_type":9,"version_end":65,"version_end_type":53,"fixed_in":9},"lt6_1_153_1~deb11u1","6.1.153-1~deb11u1"]