CVE-2025-21766: Linux Kernel

Medium severity, CVSS 5.5. EPSS: 0.5% chance of exploitation in the next 30 days.

In the Linux kernel, the following vulnerability has been resolved: ipv4: use RCU protection in __ip_rt_update_pmtu() __ip_rt_update_pmtu() must use RCU protection to make sure the net structure it reads does not disappear.

Affected products

  • Linux Linux Kernel: from 4.14.200, before 4.15 (fixed in 4.15); from 4.19.148, before 4.20 (fixed in 4.20); from 5.4.68, before 5.5 (fixed in 5.5); from 5.8.12, before 5.9 (fixed in 5.9); from 5.9.1, before 5.15.179 (fixed in 5.15.179); from 5.16, before 6.1.129 (fixed in 6.1.129); …

Published 2025-02-27. Last modified 2026-07-30.