CVE-2025-38550

HIGH

Linux Kernel 5.13-6.15.8 IPv6 Multicast Use-After-Free

Title source: llm
STIX 2.1

Description

In the Linux kernel, the following vulnerability has been resolved: ipv6: mcast: Delay put pmc->idev in mld_del_delrec() pmc->idev is still used in ip6_mc_clear_src(), so as mld_clear_delrec() does, the reference should be put after ip6_mc_clear_src() return.

Scores

CVSS v3 7.8
EPSS 0.0003
EPSS Percentile 7.9%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Details

Status published
Products (22)
debian/debian_linux 11.0
linux/Kernel 5.13.0 - 5.15.190linux
linux/Kernel 5.16.0 - 6.1.147linux
linux/Kernel 6.13.0 - 6.15.8linux
linux/Kernel 6.2.0 - 6.6.100linux
linux/Kernel 6.7.0 - 6.12.40linux
Linux/Linux < 5.13
Linux/Linux 5.13
Linux/Linux 5.15.190 - 5.15.*
Linux/Linux 6.1.147 - 6.1.*
... and 12 more
Published Aug 16, 2025
Tracked Since Feb 18, 2026