cbcvebase.
CVE-2025-21760
published 2025-02-27

CVE-2025-21760: In the Linux kernel, the following vulnerability has been resolved: ndisc: extend RCU protection in ndisc_send_skb() ndisc_send_skb() can be called without…

PriorityP347high7.8CVSS 3.1
AVLACLPRLUINSUCHIHAH
EPSS
9.12%
94.7th percentile
In the Linux kernel, the following vulnerability has been resolved: ndisc: extend RCU protection in ndisc_send_skb() ndisc_send_skb() can be called without RTNL or RCU held. Acquire rcu_read_lock() earlier, so that we can use dev_net_rcu() and avoid a potential UAF.

Affected

31 ranges· showing 25
VendorProductVersion rangeFixed in
debianlinux< linux 6.1.129-1 (bookworm)linux 6.1.129-1 (bookworm)
debianlinux-6.1< linux 6.1.129-1 (bookworm)linux 6.1.129-1 (bookworm)
linuxlinux
linuxlinux>= 1762f7e88eb34f653b4a915be99a102e347dd45e < 10a1f3fece2f0d23a3a618b72b2b4e6f408ef7d110a1f3fece2f0d23a3a618b72b2b4e6f408ef7d1
linuxlinux>= 1762f7e88eb34f653b4a915be99a102e347dd45e < 4d576202b90b1b95a7c428a80b536f91b8201bcc4d576202b90b1b95a7c428a80b536f91b8201bcc
linuxlinux>= 1762f7e88eb34f653b4a915be99a102e347dd45e < e24d225e4cb8cf108bde00b76594499b98f0a74de24d225e4cb8cf108bde00b76594499b98f0a74d
linuxlinux>= 1762f7e88eb34f653b4a915be99a102e347dd45e < a9319d800b5701e7f5e3fa71a5b7c4831fc20d6da9319d800b5701e7f5e3fa71a5b7c4831fc20d6d
linuxlinux>= 1762f7e88eb34f653b4a915be99a102e347dd45e < ae38982f521621c216fc2f5182cd091f4734641dae38982f521621c216fc2f5182cd091f4734641d
linuxlinux>= 1762f7e88eb34f653b4a915be99a102e347dd45e < 789230e5a8c1097301afc802e242c79bc8835c67789230e5a8c1097301afc802e242c79bc8835c67
linuxlinux>= 1762f7e88eb34f653b4a915be99a102e347dd45e < 04e05112f10354ffc3bb6cc796d553bab161594c04e05112f10354ffc3bb6cc796d553bab161594c
linuxlinux>= 1762f7e88eb34f653b4a915be99a102e347dd45e < ed6ae1f325d3c43966ec1b62ac1459e2b8e45640ed6ae1f325d3c43966ec1b62ac1459e2b8e45640
linuxlinux_kernel
linuxlinux_kernel
linuxlinux_kernel>= 0 < 5.10.237-15.10.237-1
linuxlinux_kernel>= 0 < 6.1.129-16.1.129-1
linuxlinux_kernel>= 0 < 6.12.16-16.12.16-1
linuxlinux_kernel>= 0 < 6.12.16-16.12.16-1
linuxlinux_kernel>= 0 < 5.4.0-216.2365.4.0-216.236
linuxlinux_kernel>= 0 < 5.15.0-140.1505.15.0-140.150
linuxlinux_kernel>= 0 < 6.8.0-78.786.8.0-78.78
linuxlinux_kernel>= 2.6.26 < 5.4.2915.4.291
linuxlinux_kernel>= 5.11 < 5.15.1795.15.179
linuxlinux_kernel>= 5.16 < 6.1.1296.1.129
linuxlinux_kernel>= 5.5 < 5.10.2355.10.235
linuxlinux_kernel>= 6.13 < 6.13.46.13.4

CVSS provenance

nvdv3.17.8HIGHCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
osv8.8HIGH
vendor_ubuntu8.8HIGH
vendor_debian7.8HIGH
vendor_msrc7.8HIGH
vendor_redhat7.8HIGH
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.