CVE-2025-21768: net: ipv6: fix dst ref loops in rpl, seg6 and ioam6 lwtunnels
In the Linux kernel, the following vulnerability has been resolved:
net: ipv6: fix dst ref loops in rpl, seg6 and ioam6 lwtunnels
Some lwtunnels have a dst cache for post-transformation dst. If the packet destination did not change we may end up recording a reference to the lwtunnel in its own cache, and the lwtunnel state will never be freed.
Discovered by the ioam6.sh test, kmemleak was recently fixed to catch per-cpu memory leaks. I'm not sure if rpl and seg6 can actually hit this, but in principle I don't see why not.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-21768?
CVE-2025-21768 has been classified with a severity level that necessitates immediate attention to mitigate potential system vulnerabilities.
How do I fix CVE-2025-21768?
To address CVE-2025-21768, ensure you update the Linux kernel to the latest stable version where the vulnerability has been resolved.
What impact does CVE-2025-21768 have on system security?
CVE-2025-21768 can lead to potential security risks involving reference loops within specific network lwtunnels, affecting data integrity.
Which versions of the Linux kernel are affected by CVE-2025-21768?
CVE-2025-21768 affects multiple versions of the Linux kernel prior to the patch that resolves this issue.
Is CVE-2025-21768 exploitable by remote attackers?
CVE-2025-21768 may introduce vulnerabilities that could potentially be exploited by remote attackers under certain conditions.