CVE-2025-21763

In the Linux kernel, the following vulnerability has been resolved: neighbour: use RCU protection in __neigh_notify() __neigh_notify() can be called without RTNL or RCU protection. Use RCU protection to avoid potential UAF.
Configurations

Configuration 1 (hide)

OR cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:6.14:rc1:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:6.14:rc2:*:*:*:*:*:*

History

21 Mar 2025, 15:45

Type Values Removed Values Added
CPE cpe:2.3:o:linux:linux_kernel:6.14:rc1:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:6.14:rc2:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
References () https://git.kernel.org/stable/c/1cbb2aa90cd3fba15ad7efb5cdda28f3d1082379 - () https://git.kernel.org/stable/c/1cbb2aa90cd3fba15ad7efb5cdda28f3d1082379 - Patch
References () https://git.kernel.org/stable/c/40d8f2f2a373b6c294ffac394d2bb814b572ead1 - () https://git.kernel.org/stable/c/40d8f2f2a373b6c294ffac394d2bb814b572ead1 - Patch
References () https://git.kernel.org/stable/c/559307d25235e24b5424778c7332451b6c741159 - () https://git.kernel.org/stable/c/559307d25235e24b5424778c7332451b6c741159 - Patch
References () https://git.kernel.org/stable/c/784eb2376270e086f7db136d154b8404edacf97b - () https://git.kernel.org/stable/c/784eb2376270e086f7db136d154b8404edacf97b - Patch
References () https://git.kernel.org/stable/c/8666e9aab801328c1408a19fbf4070609dc0695a - () https://git.kernel.org/stable/c/8666e9aab801328c1408a19fbf4070609dc0695a - Patch
References () https://git.kernel.org/stable/c/becbd5850c03ed33b232083dd66c6e38c0c0e569 - () https://git.kernel.org/stable/c/becbd5850c03ed33b232083dd66c6e38c0c0e569 - Patch
References () https://git.kernel.org/stable/c/cdd5c2a12ddad8a77ce1838ff9f29aa587de82df - () https://git.kernel.org/stable/c/cdd5c2a12ddad8a77ce1838ff9f29aa587de82df - Patch
References () https://git.kernel.org/stable/c/e1aed6be381bcd7f46d4ca9d7ef0f5f3d6a1be32 - () https://git.kernel.org/stable/c/e1aed6be381bcd7f46d4ca9d7ef0f5f3d6a1be32 - Patch
First Time Linux linux Kernel
Linux

13 Mar 2025, 13:15

Type Values Removed Values Added
Summary
  • (es) En el kernel de Linux, se ha resuelto la siguiente vulnerabilidad: neighbor: use la protección RCU en __neigh_notify() __neigh_notify() se puede llamar sin RTNL ni protección RCU. Use la protección RCU para evitar posibles UAF.
References
  • () https://git.kernel.org/stable/c/40d8f2f2a373b6c294ffac394d2bb814b572ead1 -
  • () https://git.kernel.org/stable/c/8666e9aab801328c1408a19fbf4070609dc0695a -
  • () https://git.kernel.org/stable/c/e1aed6be381bcd7f46d4ca9d7ef0f5f3d6a1be32 -

27 Feb 2025, 18:15

Type Values Removed Values Added
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 7.8
CWE CWE-416

27 Feb 2025, 03:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-02-27 03:15

Updated : 2025-03-21 15:45


NVD link : CVE-2025-21763

Mitre link : CVE-2025-21763

CVE.ORG link : CVE-2025-21763


JSON object : View

Products Affected

linux

  • linux_kernel
CWE
CWE-416

Use After Free