In the Linux kernel, the following vulnerability has been resolved:
arp: use RCU protection in arp_xmit()
arp_xmit() can be called without RTNL or RCU protection.
Use RCU protection to avoid potential UAF.
[
{
"signature_type": "Function",
"deprecated": false,
"signature_version": "v1",
"digest": {
"length": 159.0,
"function_hash": "263144031787720893120176714713928937619"
},
"source": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git@e9f4dee534eb1b225b0a120395ad9bc2afe164d3",
"target": {
"file": "net/ipv4/arp.c",
"function": "arp_xmit"
},
"id": "CVE-2025-21762-14dc6495"
},
{
"signature_type": "Line",
"deprecated": false,
"signature_version": "v1",
"digest": {
"line_hashes": [
"325007626525472826328533435520827340207",
"328964655815226870887992045235809068550",
"20914297012066318732150762814891598823",
"976471565594007996268369330721693678",
"300492012754185908285517126056337362810",
"19091133228482260209323424129981041986",
"61885838702777187551461018239835973237"
],
"threshold": 0.9
},
"source": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git@10f555e3f573d004ae9d89b3276abb58c4ede5c3",
"target": {
"file": "net/ipv4/arp.c"
},
"id": "CVE-2025-21762-544c361e"
},
{
"signature_type": "Function",
"deprecated": false,
"signature_version": "v1",
"digest": {
"length": 159.0,
"function_hash": "263144031787720893120176714713928937619"
},
"source": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git@10f555e3f573d004ae9d89b3276abb58c4ede5c3",
"target": {
"file": "net/ipv4/arp.c",
"function": "arp_xmit"
},
"id": "CVE-2025-21762-5a661f9d"
},
{
"signature_type": "Line",
"deprecated": false,
"signature_version": "v1",
"digest": {
"line_hashes": [
"325007626525472826328533435520827340207",
"328964655815226870887992045235809068550",
"20914297012066318732150762814891598823",
"976471565594007996268369330721693678",
"300492012754185908285517126056337362810",
"19091133228482260209323424129981041986",
"61885838702777187551461018239835973237"
],
"threshold": 0.9
},
"source": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git@01d1b5c9abcaff29a43f1d17a19c33eec92c7dbe",
"target": {
"file": "net/ipv4/arp.c"
},
"id": "CVE-2025-21762-963fabdd"
},
{
"signature_type": "Function",
"deprecated": false,
"signature_version": "v1",
"digest": {
"length": 159.0,
"function_hash": "263144031787720893120176714713928937619"
},
"source": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git@01d1b5c9abcaff29a43f1d17a19c33eec92c7dbe",
"target": {
"file": "net/ipv4/arp.c",
"function": "arp_xmit"
},
"id": "CVE-2025-21762-b294aaa6"
},
{
"signature_type": "Function",
"deprecated": false,
"signature_version": "v1",
"digest": {
"length": 159.0,
"function_hash": "263144031787720893120176714713928937619"
},
"source": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git@2c331718d3389b6c5f6855078ab7171849e016bd",
"target": {
"file": "net/ipv4/arp.c",
"function": "arp_xmit"
},
"id": "CVE-2025-21762-c7f89d24"
},
{
"signature_type": "Line",
"deprecated": false,
"signature_version": "v1",
"digest": {
"line_hashes": [
"325007626525472826328533435520827340207",
"328964655815226870887992045235809068550",
"20914297012066318732150762814891598823",
"976471565594007996268369330721693678",
"300492012754185908285517126056337362810",
"19091133228482260209323424129981041986",
"61885838702777187551461018239835973237"
],
"threshold": 0.9
},
"source": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git@2c331718d3389b6c5f6855078ab7171849e016bd",
"target": {
"file": "net/ipv4/arp.c"
},
"id": "CVE-2025-21762-cd53dbda"
},
{
"signature_type": "Line",
"deprecated": false,
"signature_version": "v1",
"digest": {
"line_hashes": [
"325007626525472826328533435520827340207",
"328964655815226870887992045235809068550",
"20914297012066318732150762814891598823",
"976471565594007996268369330721693678",
"300492012754185908285517126056337362810",
"19091133228482260209323424129981041986",
"61885838702777187551461018239835973237"
],
"threshold": 0.9
},
"source": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git@e9f4dee534eb1b225b0a120395ad9bc2afe164d3",
"target": {
"file": "net/ipv4/arp.c"
},
"id": "CVE-2025-21762-e9c87298"
}
]