cbcvebase.
CVE-2025-21764
published 2025-02-27

CVE-2025-21764: In the Linux kernel, the following vulnerability has been resolved: ndisc: use RCU protection in ndisc_alloc_skb() ndisc_alloc_skb() can be called without RTNL…

PriorityP336high7.8CVSS 3.1
AVLACLPRLUINSUCHIHAH
EPSS
0.26%
17.4th percentile
In the Linux kernel, the following vulnerability has been resolved: ndisc: use RCU protection in ndisc_alloc_skb() ndisc_alloc_skb() can be called without RTNL or RCU being held. Add RCU protection to avoid possible UAF.

Affected

31 ranges· showing 25
VendorProductVersion rangeFixed in
debianlinux< linux 6.1.129-1 (bookworm)linux 6.1.129-1 (bookworm)
debianlinux-6.1< linux 6.1.129-1 (bookworm)linux 6.1.129-1 (bookworm)
linuxlinux
linuxlinux>= de09334b9326632bbf1a74bfd8b01866cbbf2f61 < 96fc896d0e5b37c12808df797397fb16f308087996fc896d0e5b37c12808df797397fb16f3080879
linuxlinux>= de09334b9326632bbf1a74bfd8b01866cbbf2f61 < c30893ef3d9cde8e7e8e4fd06b53d2c935bbccb1c30893ef3d9cde8e7e8e4fd06b53d2c935bbccb1
linuxlinux>= de09334b9326632bbf1a74bfd8b01866cbbf2f61 < b870256dd2a5648d5ed2f22316b3ac29a7e5ed63b870256dd2a5648d5ed2f22316b3ac29a7e5ed63
linuxlinux>= de09334b9326632bbf1a74bfd8b01866cbbf2f61 < 3c2d705f5adf5d860aaef90cb4211c0fde2ba66d3c2d705f5adf5d860aaef90cb4211c0fde2ba66d
linuxlinux>= de09334b9326632bbf1a74bfd8b01866cbbf2f61 < 9e0ec817eb41a55327a46cd3ce331a9868d603049e0ec817eb41a55327a46cd3ce331a9868d60304
linuxlinux>= de09334b9326632bbf1a74bfd8b01866cbbf2f61 < bbec88e4108e8d6fb468d3817fa652140a44ff28bbec88e4108e8d6fb468d3817fa652140a44ff28
linuxlinux>= de09334b9326632bbf1a74bfd8b01866cbbf2f61 < cd1065f92eb7ff21b9ba5308a86f33d1670bf926cd1065f92eb7ff21b9ba5308a86f33d1670bf926
linuxlinux>= de09334b9326632bbf1a74bfd8b01866cbbf2f61 < 628e6d18930bbd21f2d4562228afe27694f66da9628e6d18930bbd21f2d4562228afe27694f66da9
linuxlinux_kernel
linuxlinux_kernel
linuxlinux_kernel>= 0 < 5.10.237-15.10.237-1
linuxlinux_kernel>= 0 < 6.1.129-16.1.129-1
linuxlinux_kernel>= 0 < 6.12.16-16.12.16-1
linuxlinux_kernel>= 0 < 6.12.16-16.12.16-1
linuxlinux_kernel>= 0 < 5.4.0-216.2365.4.0-216.236
linuxlinux_kernel>= 0 < 5.15.0-140.1505.15.0-140.150
linuxlinux_kernel>= 0 < 6.8.0-78.786.8.0-78.78
linuxlinux_kernel>= 3.9 < 5.4.2915.4.291
linuxlinux_kernel>= 5.11 < 5.15.1795.15.179
linuxlinux_kernel>= 5.16 < 6.1.1296.1.129
linuxlinux_kernel>= 5.5 < 5.10.2355.10.235
linuxlinux_kernel>= 6.13 < 6.13.46.13.4

CVSS provenance

nvdv3.17.8HIGHCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
osv8.8HIGH
vendor_ubuntu8.8HIGH
vendor_debian7.8HIGH
vendor_redhat7.8HIGH
vendor_msrc6.6MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.