PT-2025-8871 · Linux+10 · Linux Kernel+10

Published

2025-02-07

·

Updated

2026-04-20

·

CVE-2025-21759

CVSS v3.1

7.8

High

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Linux kernel (affected versions not specified)
Description A potential issue in the Linux kernel has been identified, related to the igmp6 send() function. This function can be called without the necessary synchronization, potentially leading to a use-after-free (UAF) condition. To address this, RCU protection has been extended to ensure safe access to the net pointer. Additionally, the allocation method for sending skb has been changed from sock alloc send skb() to alloc skb() due to the use of GFP KERNEL allocations, which can sleep.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Use After Free

Weakness Enumeration

Related Identifiers

ALSA-2025:10371
ALSA-2025:10379
ALSA-2025:13589
ALSA-2025:13590
ALT-PU-2025-12647
AZL-58968
AZL-59064
BDU:2025-04522
CESA-2025_13589
CESA-2025_13590
CVE-2025-21759
ECHO-D530-3B64-4826
INFSA-2025_10379
INFSA-2025_13589
INFSA-2025_13590
OESA-2025-1446
OESA-2025-1450
OESA-2025-1465
OESA-2025-2118
OESA-2025-2119
OPENSUSE-SU-2025_1177-1
OPENSUSE-SU-2025_1178-1
OPENSUSE-SU-2025_1180-1
RHSA-2025:10371
RHSA-2025:10379
RHSA-2025:10829
RHSA-2025:10830
RHSA-2025:11245
RHSA-2025:12209
RHSA-2025:12311
RHSA-2025:13589
RHSA-2025:13590
RHSA-2025:14985
RHSA-2025_10379
RHSA-2025_13589
RHSA-2025_13590
SUSE-SU-2025:01919-1
SUSE-SU-2025:01951-1
SUSE-SU-2025:01967-1
SUSE-SU-2025:1177-1
SUSE-SU-2025:1178-1
SUSE-SU-2025:1180-1
SUSE-SU-2025:1293-1
SUSE-SU-2025:20190-1
SUSE-SU-2025:20192-1
SUSE-SU-2025:20260-1
SUSE-SU-2025:20270-1
SUSE-SU-2025_01951-1
SUSE-SU-2025_01967-1
SUSE-SU-2025_1177-1
SUSE-SU-2025_1178-1
SUSE-SU-2025_1180-1
SUSE-SU-2025_1293-1
USN-7521-1
USN-7521-2
USN-7521-3
USN-7703-1
USN-7703-2
USN-7703-3
USN-7703-4
USN-7719-1
USN-7737-1

Affected Products

Alt Linux
Almalinux
Astra Linux
Centos
Debian
Linuxmint
Linux Kernel
Red Hat
Rocky Linux
Suse
Ubuntu