PT-2025-34399 · Linux+1 · Linux Kernel+1

Syzbot

·

Published

2025-07-26

·

Updated

2025-08-22

·

CVE-2025-38638

CVSS v2.0

6.0

Medium

VectorAV:L/AC:H/Au:S/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions: Linux kernel versions prior to 6.16.0-rc7-syzkaller
Description: The Linux kernel contained a flaw in the inet6 rt notify() function within the IPv6 networking stack. Specifically, the function could be called while under RCU protection, potentially leading to a race condition where a route could change concurrently with the function's execution. This could result in rt6 fill node() returning an -EMSGSIZE error. The issue was addressed by adding retry logic to resize the skb when this condition occurs, removing a related warning that was triggered by syzbot.
Recommendations: Update to a version newer than 6.16.0-rc7-syzkaller.

Exploit

Fix

Improper Locking

Weakness Enumeration

Related Identifiers

BDU:2026-01554
CVE-2025-38638

Affected Products

Astra Linux
Linux Kernel