cbcvebase.
CVE-2025-21762
published 2025-02-27

CVE-2025-21762: In the Linux kernel, the following vulnerability has been resolved: arp: use RCU protection in arp_xmit() arp_xmit() can be called without RTNL or RCU…

PriorityP338high8.1CVSS 3.1
AVNACHPRNUINSUCHIHAH
EPSS
0.61%
45.9th percentile
In the Linux kernel, the following vulnerability has been resolved: arp: use RCU protection in arp_xmit() arp_xmit() can be called without RTNL or RCU protection. Use RCU protection to avoid potential UAF.

Affected

31 ranges· showing 25
VendorProductVersion rangeFixed in
debianlinux< linux 6.1.129-1 (bookworm)linux 6.1.129-1 (bookworm)
debianlinux-6.1< linux 6.1.129-1 (bookworm)linux 6.1.129-1 (bookworm)
linuxlinux
linuxlinux>= 29a26a56803855a79dbd028cd61abee56237d6e5 < 10f555e3f573d004ae9d89b3276abb58c4ede5c310f555e3f573d004ae9d89b3276abb58c4ede5c3
linuxlinux>= 29a26a56803855a79dbd028cd61abee56237d6e5 < 307cd1e2d3cb1cbc6c40c679cada6d7168b18431307cd1e2d3cb1cbc6c40c679cada6d7168b18431
linuxlinux>= 29a26a56803855a79dbd028cd61abee56237d6e5 < d9366ac2f956a1948b68c0500f84a3462ff2ed8ad9366ac2f956a1948b68c0500f84a3462ff2ed8a
linuxlinux>= 29a26a56803855a79dbd028cd61abee56237d6e5 < f189654459423d4d48bef2d120b4bfba559e6039f189654459423d4d48bef2d120b4bfba559e6039
linuxlinux>= 29a26a56803855a79dbd028cd61abee56237d6e5 < e9f4dee534eb1b225b0a120395ad9bc2afe164d3e9f4dee534eb1b225b0a120395ad9bc2afe164d3
linuxlinux>= 29a26a56803855a79dbd028cd61abee56237d6e5 < 01d1b5c9abcaff29a43f1d17a19c33eec92c7dbe01d1b5c9abcaff29a43f1d17a19c33eec92c7dbe
linuxlinux>= 29a26a56803855a79dbd028cd61abee56237d6e5 < 2c331718d3389b6c5f6855078ab7171849e016bd2c331718d3389b6c5f6855078ab7171849e016bd
linuxlinux>= 29a26a56803855a79dbd028cd61abee56237d6e5 < a42b69f692165ec39db42d595f4f65a4c8f42e44a42b69f692165ec39db42d595f4f65a4c8f42e44
linuxlinux_kernel
linuxlinux_kernel
linuxlinux_kernel>= 0 < 5.10.237-15.10.237-1
linuxlinux_kernel>= 0 < 6.1.129-16.1.129-1
linuxlinux_kernel>= 0 < 6.12.16-16.12.16-1
linuxlinux_kernel>= 0 < 6.12.16-16.12.16-1
linuxlinux_kernel>= 0 < 5.4.0-216.2365.4.0-216.236
linuxlinux_kernel>= 0 < 5.15.0-140.1505.15.0-140.150
linuxlinux_kernel>= 0 < 6.8.0-78.786.8.0-78.78
linuxlinux_kernel>= 4.4 < 5.4.2915.4.291
linuxlinux_kernel>= 5.11 < 5.15.1795.15.179
linuxlinux_kernel>= 5.16 < 6.1.1296.1.129
linuxlinux_kernel>= 5.5 < 5.10.2355.10.235
linuxlinux_kernel>= 6.13 < 6.13.46.13.4

CVSS provenance

nvdv3.18.1HIGHCVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
osv8.8HIGH
vendor_ubuntu8.8HIGH
vendor_debian7.8HIGH
vendor_msrc7.8HIGH
vendor_redhat7.8HIGH
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.