{"id":"CVE-2025-21759","title":"In the Linux kernel, the following vulnerability has been resolved:\n\nipv6: mcast: extend RCU protection in igmp6_send()\n\nigmp6_send() can be called without RTNL or RCU being held.\n\nExtend RCU protection so that we can safely fetch the ne…","summary":"In the Linux kernel, the following vulnerability has been resolved:\n\nipv6: mcast: extend RCU protection in igmp6_send()\n\nigmp6_send() can be called without RTNL or RCU being held.\n\nExtend RCU protection so that we can safely fetch the ne…","severity":"high","cvss":7.8,"cvssVector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","cwe":["CWE-416"],"vendor":"linux","product":"linux_kernel","affected":["linux_kernel >= 2.6.26, < 6.6.79","linux_kernel >= 6.7, < 6.12.16","linux_kernel >= 6.13, < 6.13.4","linux_kernel = 6.14"],"patched":["linux_kernel 6.13.4"],"published":"2025-02-27","updated":"2026-10-03","sourceUpdated":"2026-10-03T11:17:32.400","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2025-21759","references":[{"url":"https://git.kernel.org/stable/c/087c1faa594fa07a66933d750c0b2610aa1a2946","label":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/0bf8e2f3768629d437a32cb824149e6e98254381","label":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/638e8fe3563a82f298fe537a28d5342a97278cf1","label":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/6901bbb169e3add6c037218d996790cef6b3d650","label":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/7e0a818ecc4d62e7fb668ea02de0bfe8ba0b7dff","label":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/81b25a07ebf53f9ef4ca8f3d96a8ddb94561dd5a","label":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/8e92d6a413feaf968a33f0b439ecf27404407458","label":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}],"tags":["nvd","cve.org"],"ssvc":{"exploitation":"none","automatable":"no","technicalImpact":"total","timestamp":"2025-02-27T17:57:46.460072Z"},"epss":0.07773,"epssPercentile":0.94472,"ingestedAt":"2026-10-03T11:43:42.106Z","slug":"CVE-2025-21759","body":"## Overview\n\nIn the Linux kernel, the following vulnerability has been resolved:\n\nipv6: mcast: extend RCU protection in igmp6_send()\n\nigmp6_send() can be called without RTNL or RCU being held.\n\nExtend RCU protection so that we can safely fetch the net pointer\nand avoid a potential UAF.\n\nNote that we no longer can use sock_alloc_send_skb() because\nipv6.igmp_sk uses GFP_KERNEL allocations which can sleep.\n\nInstead use alloc_skb() and charge the net->ipv6.igmp_sk\nsocket under RCU protection.\n\n## Affected\n\n- `linux_kernel >= 2.6.26, < 6.6.79`\n- `linux_kernel >= 6.7, < 6.12.16`\n- `linux_kernel >= 6.13, < 6.13.4`\n- `linux_kernel = 6.14`\n\n## Remediation\n\nUpgrade past the affected range:\n\n- `linux_kernel 6.13.4`","depth":"twilight","depthScore":44,"depthScoreParts":{"impact":42.9,"likelihood":1.6,"exploitation":0,"ransomware":0},"changes":[]}