CVE-2025-21759: ipv6: mcast: extend RCU protection in igmp6_send()
In the Linux kernel, the following vulnerability has been resolved:
ipv6: mcast: extend RCU protection in igmp6send()
igmp6send() can be called without RTNL or RCU being held.
Extend RCU protection so that we can safely fetch the net pointer and avoid a potential UAF.
Note that we no longer can use sockallocsendskb() because ipv6.igmpsk uses GFPKERNEL allocations which can sleep.
Instead use allocskb() and charge the net->ipv6.igmpsk socket under RCU protection.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 6.6.82.1-1
Event History
Frequently Asked Questions
What is the severity of CVE-2025-21759?
CVE-2025-21759 is classified as a moderate severity vulnerability in the Linux kernel.
How do I fix CVE-2025-21759?
To fix CVE-2025-21759, update your Linux kernel to the latest version that includes the patch for this vulnerability.
What type of vulnerability is CVE-2025-21759?
CVE-2025-21759 is a use-after-free (UAF) vulnerability related to the igmp6_send() function in the Linux kernel.
Who is affected by CVE-2025-21759?
CVE-2025-21759 affects systems running affected versions of the Linux kernel that utilize IPv6 multicast.
What components are involved in CVE-2025-21759?
CVE-2025-21759 involves the RCU (Read-Copy-Update) protection mechanism within the igmp6_send() function.