In the Linux kernel, the following vulnerability has been resolved:
ipv6: mcast: add RCU protection to mld_newpack()
mld_newpack() can be called without RTNL or RCU being held.
Note that we no longer can use sock_alloc_send_skb() because
ipv6.igmp_sk uses GFP_KERNEL allocations which can sleep.
Instead use alloc_skb() and charge the net->ipv6.igmp_sk
socket under RCU protection.
CVE ID: CVE-2025-21758
Vendor: Linux, Linux
Product: Linux, Linux
EPSS Score: 0.04% (probability of being exploited)
EPSS Percentile: 9.05% (scored less or equal to compared to others)
EPSS Date: 2025-03-27 (when was this score calculated)