# CVE-2025-21758

## Summary

- **CVE ID:** CVE-2025-21758
- **Severity:** HIGH
- **CVSS Score:** 7.8 (CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H)
- **CWE:** N/A
- **Published:** Feb 27, 2025
- **Last Modified:** Sep 8, 2026

## Description

In the Linux kernel, the following vulnerability has been resolved:

ipv6: mcast: add RCU protection to mld_newpack()

mld_newpack() can be called without RTNL or RCU being held.

Note that we no longer can use sock_alloc_send_skb() because
ipv6.igmp_sk uses GFP_KERNEL allocations which can sleep.

Instead use alloc_skb() and charge the net->ipv6.igmp_sk
socket under RCU protection.

## Affected Products

- Linux — Linux (b8ad0cbc58f703972e9e37c4e2a8081dd7e6a551)
- Linux — Linux (2.6.26)
- Linux — Linux (0)
- Linux — Linux (5.15.179)
- Linux — Linux (6.1.129)
- Linux — Linux (6.6.79)
- Linux — Linux (6.12.16)
- Linux — Linux (6.13.4)
- Linux — Linux (6.14)

## References

- [CNA](https://git.kernel.org/stable/c/29fa42197f26a97cde29fa8c40beddf44ea5c8f3)
- [CNA](https://git.kernel.org/stable/c/e8af3632a7f2da83e27b083f787bced1faba00b1)
- [CNA](https://git.kernel.org/stable/c/1b91c597b0214b1b462eb627ec02658c944623f2)
- [CNA](https://git.kernel.org/stable/c/25195f9d5ffcc8079ad743a50c0409dbdc48d98a)
- [CNA](https://git.kernel.org/stable/c/d60d493b0e65647e0335e6a7c4547abcea7df8e9)
- [CNA](https://git.kernel.org/stable/c/a527750d877fd334de87eef81f1cb5f0f0ca3373)
- [CVE](https://lists.debian.org/debian-lts-announce/2025/03/msg00028.html)
- [siemens-SADP](https://cert-portal.siemens.com/productcert/html/ssa-082556.html)
- [siemens-SADP](https://cert-portal.siemens.com/productcert/html/ssa-019113.html)

## Exploitation Prediction (EPSS)

- **EPSS Score:** 13.71%
- **EPSS Percentile:** 96.3

---
_Exported from OnDuty AI Vulnerability Intelligence on 2026-09-19._