Executive brief
A vulnerability was identified in the Linux kernel's IPv6 networking component. The issue involves improper synchronization when handling multicast network traffic, which could allow a local user to cause a system crash or instability. This affects the reliability and availability of systems running impacted versions of the Linux operating system.
Technical details
A concurrency issue exists in the net/ipv6/mcast.c component of the Linux kernel. Specifically, the mld_newpack() function could be called without holding the necessary RTNL or RCU locks, leading to potential use-after-free or race conditions when accessing network namespace structures. The fix introduces RCU protection within mld_newpack() and switches from sock_alloc_send_skb() to alloc_skb() to avoid sleeping during socket allocation while under RCU protection. An attacker with local access could exploit this to trigger a kernel panic (Denial of Service).
Affected products
- Linux Linux Kernel versions from 2.6.26 up to 5.15.179, 5.16 up to 6.1.129, 6.2 up to 6.6.79, 6.7 up to 6.12.16, 6.13 up to 6.13.4
Timeline
- 2025-02-12: patched: Initial patch authored by Eric Dumazet
- 2025-02-26: disclosed: CVE assigned and published by kernel.org
- 2025-02-27: advisory: NVD publication date
References
- https://git.kernel.org/stable/c/1b91c597b0214b1b462eb627ec02658c944623f2
- https://git.kernel.org/stable/c/25195f9d5ffcc8079ad743a50c0409dbdc48d98a
- https://git.kernel.org/stable/c/29fa42197f26a97cde29fa8c40beddf44ea5c8f3
- https://git.kernel.org/stable/c/a527750d877fd334de87eef81f1cb5f0f0ca3373
- https://git.kernel.org/stable/c/d60d493b0e65647e0335e6a7c4547abcea7df8e9
- https://git.kernel.org/stable/c/e8af3632a7f2da83e27b083f787bced1faba00b1
- https://lists.debian.org/debian-lts-announce/2025/03/msg00028.html