Junglewise Threat Intelligence

CVE-2025-21758: Linux Kernel race condition in ipv6 mcast mld_newpack

CVE-2025-21758 · Severity: medium · CVSS 5.5 · Published 2025-02-27

Technologies: Linux Kernel. Vendors: Linux.

Executive brief

A vulnerability was identified in the Linux kernel's IPv6 networking component. The issue involves improper synchronization when handling multicast network traffic, which could allow a local user to cause a system crash or instability. This affects the reliability and availability of systems running impacted versions of the Linux operating system.

Technical details

A concurrency issue exists in the net/ipv6/mcast.c component of the Linux kernel. Specifically, the mld_newpack() function could be called without holding the necessary RTNL or RCU locks, leading to potential use-after-free or race conditions when accessing network namespace structures. The fix introduces RCU protection within mld_newpack() and switches from sock_alloc_send_skb() to alloc_skb() to avoid sleeping during socket allocation while under RCU protection. An attacker with local access could exploit this to trigger a kernel panic (Denial of Service).

Affected products

  • Linux Linux Kernel versions from 2.6.26 up to 5.15.179, 5.16 up to 6.1.129, 6.2 up to 6.6.79, 6.7 up to 6.12.16, 6.13 up to 6.13.4

Timeline

  • 2025-02-12: patched: Initial patch authored by Eric Dumazet
  • 2025-02-26: disclosed: CVE assigned and published by kernel.org
  • 2025-02-27: advisory: NVD publication date

References

Related threats