CVE-2025-21763

Source
https://cve.org/CVERecord?id=CVE-2025-21763
Import Source
https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2025-21763.json
JSON Data
https://api.test.osv.dev/v1/vulns/CVE-2025-21763
Downstream
Related
Published
2025-02-27T02:18:15.078Z
Modified
2026-07-11T03:55:04.080965247Z
Severity
  • 7.8 (High) CVSS_V3 - CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H CVSS Calculator
Summary
neighbour: use RCU protection in __neigh_notify()
Details

In the Linux kernel, the following vulnerability has been resolved:

neighbour: use RCU protection in _neighnotify()

_neighnotify() can be called without RTNL or RCU protection.

Use RCU protection to avoid potential UAF.

Database specific
{
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2025/21xxx/CVE-2025-21763.json",
    "cna_assigner": "Linux"
}
References

Affected packages

Git / git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git

Affected ranges

Type
GIT
Repo
https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git
Events
Introduced
426b5303eb435d98b9bee37a807be386bc2b3320
Fixed
e1aed6be381bcd7f46d4ca9d7ef0f5f3d6a1be32
Fixed
8666e9aab801328c1408a19fbf4070609dc0695a
Fixed
40d8f2f2a373b6c294ffac394d2bb814b572ead1
Fixed
784eb2376270e086f7db136d154b8404edacf97b
Fixed
1cbb2aa90cd3fba15ad7efb5cdda28f3d1082379
Fixed
cdd5c2a12ddad8a77ce1838ff9f29aa587de82df
Fixed
559307d25235e24b5424778c7332451b6c741159
Fixed
becbd5850c03ed33b232083dd66c6e38c0c0e569

Database specific

source
"https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2025-21763.json"

Linux / Kernel

Package

Name
Kernel

Affected ranges

Type
ECOSYSTEM
Events
Introduced
2.6.25
Fixed
5.4.291
Type
ECOSYSTEM
Events
Introduced
5.5.0
Fixed
5.10.235
Type
ECOSYSTEM
Events
Introduced
5.11.0
Fixed
5.15.179
Type
ECOSYSTEM
Events
Introduced
5.16.0
Fixed
6.1.129
Type
ECOSYSTEM
Events
Introduced
6.2.0
Fixed
6.6.79
Type
ECOSYSTEM
Events
Introduced
6.7.0
Fixed
6.12.16
Type
ECOSYSTEM
Events
Introduced
6.13.0
Fixed
6.13.4

Database specific

source
"https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2025-21763.json"