Junglewise Threat Intelligence

CVE-2025-21760: Linux Kernel use-after-free in IPv6 Neighbor Discovery

CVE-2025-21760 · Severity: high · CVSS 7.8 · Published 2025-02-27

Technologies: Linux Kernel. Vendors: Linux.

Executive brief

A vulnerability exists in the Linux kernel's networking component responsible for IPv6 Neighbor Discovery. This component helps devices on a local network find each other and exchange configuration information. An attacker with local access could exploit this flaw to cause a system crash or potentially gain unauthorized access to sensitive information, impacting the overall stability and security of the operating system.

Technical details

A use-after-free (UAF) vulnerability exists in net/ipv6/ndisc.c within the ndisc_send_skb() function. The root cause is that ndisc_send_skb() could be invoked without holding the RTNL lock or an RCU read lock, leading to unsafe access of network namespace data via dev_net(). An attacker with local access can trigger this condition to achieve a use-after-free, potentially resulting in arbitrary code execution or a kernel panic. The fix involves extending RCU protection by acquiring rcu_read_lock() earlier in the function and using dev_net_rcu() to safely access the network namespace. Patches have been released for multiple stable kernel branches.

Affected products

  • Linux Linux Kernel 2.6.26 to 5.4.291, 5.5 to 5.10.235, 5.11 to 5.15.179, 5.16 to 6.1.129, 6.2 to 6.6.79, 6.7 to 6.12.16, 6.13 to 6.13.4

Timeline

  • 2025-02-07: patched: Initial patch authored by Eric Dumazet
  • 2025-02-26: disclosed: CVE-2025-21760 assigned and published
  • 2025-02-27: advisory: NVD publication date

References

Related threats