PT-2025-8872 · Linux+7 · Linux Kernel+7
CVSS v3.1
8.1
High
| Vector | AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Linux kernel (affected versions not specified)
Description
A Use-After-Free (UAF) issue exists in the IPv6 protocol implementation within the
net/ipv6/ndisc.c module. The ndisc send skb() function can be called without holding RTNL (Routing Netlink) or RCU (Read-Copy-Update) locks, which allows the reuse of previously freed memory. This could impact the confidentiality, integrity, and availability of protected information.Recommendations
Update the Linux kernel to a version where the
ndisc send skb() function is modified to acquire rcu read lock() earlier to ensure proper protection when using dev net rcu().Exploit
Fix
DoS
Use After Free
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Alt Linux
Astra Linux
Debian
Linuxmint
Linux Kernel
Red Os
Suse
Ubuntu