In the Linux kernel, the following vulnerability has been resolved:
arp: use RCU protection in arp_xmit()
arp_xmit() can be called without RTNL or RCU protection.
Use RCU protection to avoid potential UAF.
{
"osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2025/21xxx/CVE-2025-21762.json",
"cna_assigner": "Linux"
}[
{
"signature_type": "Line",
"digest": {
"line_hashes": [
"325007626525472826328533435520827340207",
"328964655815226870887992045235809068550",
"20914297012066318732150762814891598823",
"976471565594007996268369330721693678",
"300492012754185908285517126056337362810",
"19091133228482260209323424129981041986",
"61885838702777187551461018239835973237"
],
"threshold": 0.9
},
"signature_version": "v1",
"id": "CVE-2025-21762-d93d909e",
"deprecated": false,
"source": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git@307cd1e2d3cb1cbc6c40c679cada6d7168b18431",
"target": {
"file": "net/ipv4/arp.c"
}
},
{
"signature_type": "Function",
"digest": {
"function_hash": "263144031787720893120176714713928937619",
"length": 159.0
},
"signature_version": "v1",
"id": "CVE-2025-21762-e4911bed",
"deprecated": false,
"source": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git@307cd1e2d3cb1cbc6c40c679cada6d7168b18431",
"target": {
"file": "net/ipv4/arp.c",
"function": "arp_xmit"
}
}
]
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2025-21762.json"