---
id: CVE-2025-21759
title: |-
  In the Linux kernel, the following vulnerability has been resolved:

  ipv6: mcast: extend RCU protection in igmp6_send()

  igmp6_send() can be called without RTNL or RCU being held.

  Extend RCU protection so that we can safely fetch the ne…
summary: |-
  In the Linux kernel, the following vulnerability has been resolved:

  ipv6: mcast: extend RCU protection in igmp6_send()

  igmp6_send() can be called without RTNL or RCU being held.

  Extend RCU protection so that we can safely fetch the ne…
severity: high
cvss: 7.8
cvssVector: 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H'
cwe:
  - CWE-416
vendor: linux
product: linux_kernel
affected:
  - 'linux_kernel >= 2.6.26, < 6.6.79'
  - 'linux_kernel >= 6.7, < 6.12.16'
  - 'linux_kernel >= 6.13, < 6.13.4'
  - linux_kernel = 6.14
patched:
  - linux_kernel 6.13.4
published: '2025-02-27'
updated: '2026-10-03'
sourceUpdated: '2026-10-03T11:17:32.400'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2025-21759'
references:
  - url: 'https://git.kernel.org/stable/c/087c1faa594fa07a66933d750c0b2610aa1a2946'
    label: 416baaa9-dc9f-4396-8d5f-8c081fb06d67
  - url: 'https://git.kernel.org/stable/c/0bf8e2f3768629d437a32cb824149e6e98254381'
    label: 416baaa9-dc9f-4396-8d5f-8c081fb06d67
  - url: 'https://git.kernel.org/stable/c/638e8fe3563a82f298fe537a28d5342a97278cf1'
    label: 416baaa9-dc9f-4396-8d5f-8c081fb06d67
  - url: 'https://git.kernel.org/stable/c/6901bbb169e3add6c037218d996790cef6b3d650'
    label: 416baaa9-dc9f-4396-8d5f-8c081fb06d67
  - url: 'https://git.kernel.org/stable/c/7e0a818ecc4d62e7fb668ea02de0bfe8ba0b7dff'
    label: 416baaa9-dc9f-4396-8d5f-8c081fb06d67
  - url: 'https://git.kernel.org/stable/c/81b25a07ebf53f9ef4ca8f3d96a8ddb94561dd5a'
    label: 416baaa9-dc9f-4396-8d5f-8c081fb06d67
  - url: 'https://git.kernel.org/stable/c/8e92d6a413feaf968a33f0b439ecf27404407458'
    label: 416baaa9-dc9f-4396-8d5f-8c081fb06d67
tags:
  - nvd
  - cve.org
ssvc:
  exploitation: none
  automatable: 'no'
  technicalImpact: total
  timestamp: '2025-02-27T17:57:46.460072Z'
epss: 0.07773
epssPercentile: 0.94472
ingestedAt: '2026-10-03T11:43:42.106Z'
---

## Overview

In the Linux kernel, the following vulnerability has been resolved:

ipv6: mcast: extend RCU protection in igmp6_send()

igmp6_send() can be called without RTNL or RCU being held.

Extend RCU protection so that we can safely fetch the net pointer
and avoid a potential UAF.

Note that we no longer can use sock_alloc_send_skb() because
ipv6.igmp_sk uses GFP_KERNEL allocations which can sleep.

Instead use alloc_skb() and charge the net->ipv6.igmp_sk
socket under RCU protection.

## Affected

- `linux_kernel >= 2.6.26, < 6.6.79`
- `linux_kernel >= 6.7, < 6.12.16`
- `linux_kernel >= 6.13, < 6.13.4`
- `linux_kernel = 6.14`

## Remediation

Upgrade past the affected range:

- `linux_kernel 6.13.4`
