CVE-2025-21766

ipv4: use RCU protection in __ip_rt_update_pmtu()

References

Notes

 carnil> Introduced in 2fbc6e89b2f1 ("ipv4: Update exception handling for multipath
 carnil> routes via same device")
 carnil> 1de6b15a434c ("Namespaceify min_pmtu sysctl"). Vulnerable versions: 4.14.200
 carnil> 4.19.148 5.4.68 5.8.12 5.9-rc7.

Bugs

Status

Branch Status
upstream released (6.14-rc3) [139512191bd06f1b496117c76372b2ce372c9a41]
6.18-upstream-stable N/A "Fixed before branching point"
6.17-upstream-stable N/A "Fixed before branching point"
6.13-upstream-stable released (6.13.4) [a39f61d212d822b3062d7f70fa0588e50e55664e]
6.12-upstream-stable released (6.12.16) [4583748b65dee4d61bd50a2214715b4237bc152a]
6.6-upstream-stable released (6.6.79) [9b1766d1ff5fe496aabe9fc5f4e34e53f35c11c4]
6.1-upstream-stable released (6.1.129) [ea07480b23225942208f1b754fea1e7ec486d37e]
5.10-upstream-stable needed
sid released (6.12.16-1)
6.12-trixie-security N/A "Fixed before branching point"
6.1-bookworm-security released (6.1.129-1)
5.10-bullseye-security needed