# CVE-2025-21760

## Summary

- **CVE ID:** CVE-2025-21760
- **Severity:** HIGH
- **CVSS Score:** 8.1 (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H)
- **CWE:** N/A
- **Published:** Feb 27, 2025
- **Last Modified:** Sep 8, 2026

## Description

In the Linux kernel, the following vulnerability has been resolved:

ndisc: extend RCU protection in ndisc_send_skb()

ndisc_send_skb() can be called without RTNL or RCU held.

Acquire rcu_read_lock() earlier, so that we can use dev_net_rcu()
and avoid a potential UAF.

## Affected Products

- Linux — Linux (1762f7e88eb34f653b4a915be99a102e347dd45e)
- Linux — Linux (2.6.26)
- Linux — Linux (0)
- Linux — Linux (5.4.291)
- Linux — Linux (5.10.235)
- Linux — Linux (5.15.179)
- Linux — Linux (6.1.129)
- Linux — Linux (6.6.79)
- Linux — Linux (6.12.16)
- Linux — Linux (6.13.4)
- Linux — Linux (6.14)

## References

- [CNA](https://git.kernel.org/stable/c/10a1f3fece2f0d23a3a618b72b2b4e6f408ef7d1)
- [CNA](https://git.kernel.org/stable/c/4d576202b90b1b95a7c428a80b536f91b8201bcc)
- [CNA](https://git.kernel.org/stable/c/e24d225e4cb8cf108bde00b76594499b98f0a74d)
- [CNA](https://git.kernel.org/stable/c/a9319d800b5701e7f5e3fa71a5b7c4831fc20d6d)
- [CNA](https://git.kernel.org/stable/c/ae38982f521621c216fc2f5182cd091f4734641d)
- [CNA](https://git.kernel.org/stable/c/789230e5a8c1097301afc802e242c79bc8835c67)
- [CNA](https://git.kernel.org/stable/c/04e05112f10354ffc3bb6cc796d553bab161594c)
- [CNA](https://git.kernel.org/stable/c/ed6ae1f325d3c43966ec1b62ac1459e2b8e45640)
- [CVE](https://lists.debian.org/debian-lts-announce/2025/05/msg00030.html)
- [CVE](https://lists.debian.org/debian-lts-announce/2025/03/msg00028.html)
- [siemens-SADP](https://cert-portal.siemens.com/productcert/html/ssa-265688.html)
- [siemens-SADP](https://cert-portal.siemens.com/productcert/html/ssa-019113.html)

## Exploitation Prediction (EPSS)

- **EPSS Score:** 36.85%
- **EPSS Percentile:** 98.4

---
_Exported from OnDuty AI Vulnerability Intelligence on 2026-09-17._