CVE-2025-38550: Debian Linux

High severity, CVSS 7.8. EPSS: 0.2% chance of exploitation in the next 30 days.

In the Linux kernel, the following vulnerability has been resolved: ipv6: mcast: Delay put pmc->idev in mld_del_delrec() pmc->idev is still used in ip6_mc_clear_src(), so as mld_clear_delrec() does, the reference should be put after ip6_mc_clear_src() return.

Affected products

  • Debian Debian Linux: version 11.0 only
  • Linux Linux Kernel: from 5.13, before 5.15.190 (fixed in 5.15.190); from 5.16, before 6.1.147 (fixed in 6.1.147); from 6.2, before 6.6.100 (fixed in 6.6.100); from 6.7, before 6.12.40 (fixed in 6.12.40); from 6.13, before 6.15.8 (fixed in 6.15.8); version 6.16 only

Published 2025-08-16. Last modified 2026-07-30.