PT-2025-34399 · Linux+1 · Linux Kernel+1
Syzbot
·
Published
2025-07-26
·
Updated
2025-08-22
·
CVE-2025-38638
CVSS v2.0
6.0
Medium
| Vector | AV:L/AC:H/Au:S/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions:
Linux kernel versions prior to 6.16.0-rc7-syzkaller
Description:
The Linux kernel contained a flaw in the
inet6 rt notify() function within the IPv6 networking stack. Specifically, the function could be called while under RCU protection, potentially leading to a race condition where a route could change concurrently with the function's execution. This could result in rt6 fill node() returning an -EMSGSIZE error. The issue was addressed by adding retry logic to resize the skb when this condition occurs, removing a related warning that was triggered by syzbot.Recommendations:
Update to a version newer than 6.16.0-rc7-syzkaller.
Exploit
Fix
Improper Locking
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Astra Linux
Linux Kernel