# CVE-2025-21765

## Summary

- **CVE ID:** CVE-2025-21765
- **Severity:** HIGH
- **CVSS Score:** 8.1 (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H)
- **CWE:** N/A
- **Published:** Feb 27, 2025
- **Last Modified:** Sep 8, 2026

## Description

In the Linux kernel, the following vulnerability has been resolved:

ipv6: use RCU protection in ip6_default_advmss()

ip6_default_advmss() needs rcu protection to make
sure the net structure it reads does not disappear.

## Affected Products

- Linux — Linux (5578689a4e3c04f2d43ea39736fd3fa396d80c6e)
- Linux — Linux (2.6.26)
- Linux — Linux (0)
- Linux — Linux (5.4.291)
- Linux — Linux (5.10.235)
- Linux — Linux (5.15.179)
- Linux — Linux (6.1.129)
- Linux — Linux (6.6.79)
- Linux — Linux (6.12.16)
- Linux — Linux (6.13.4)
- Linux — Linux (6.14)

## References

- [CNA](https://git.kernel.org/stable/c/78ad057472d8c76e0602402269222f9f9c698790)
- [CNA](https://git.kernel.org/stable/c/d02f30d220ef9511568a48dba8a9004c65f8d904)
- [CNA](https://git.kernel.org/stable/c/28de355b63ad42309ed5a03ee7c436c90512265b)
- [CNA](https://git.kernel.org/stable/c/84212387caadb211cd9dadd6fd5563bd37dc1f5e)
- [CNA](https://git.kernel.org/stable/c/4176a68b0db8fc74ac14fcd00ba8231371051dc2)
- [CNA](https://git.kernel.org/stable/c/713a40c892f40300d63691d9f85b2a23b48fe1e8)
- [CNA](https://git.kernel.org/stable/c/550ed693f47370502a71b85382e7f9e6417300b8)
- [CNA](https://git.kernel.org/stable/c/3c8ffcd248da34fc41e52a46e51505900115fc2a)
- [CVE](https://lists.debian.org/debian-lts-announce/2025/05/msg00030.html)
- [CVE](https://lists.debian.org/debian-lts-announce/2025/03/msg00028.html)
- [siemens-SADP](https://cert-portal.siemens.com/productcert/html/ssa-265688.html)
- [siemens-SADP](https://cert-portal.siemens.com/productcert/html/ssa-082556.html)
- [siemens-SADP](https://cert-portal.siemens.com/productcert/html/ssa-019113.html)

## Exploitation Prediction (EPSS)

- **EPSS Score:** 0.60%
- **EPSS Percentile:** 47.3

---
_Exported from OnDuty AI Vulnerability Intelligence on 2026-09-18._