Answer in brief
CVE-2025-21766 records a Unknown severity vulnerability in ipv4: use RCU protection in __ip_rt_update_pmtu(). The current sources do not mark it as known exploited. The current feed maps Linux/Linux (generic), Linux/Linux (generic), Siemens/SIMATIC S7-1500 CPU 1518-4 PN/DP MFP (generic), Siemens/SIMATIC S7-1500 CPU 1518F-4 PN/DP MFP (generic) and additional mapped packages. Check affected ranges and fixed versions before updating.
Analysis pending evidence review
HOL Guard separates source facts from reviewed analysis. See the methodology.
A CVSS score is not reported in the current record. The current sources do not mark it as known exploited. Treat this as a source-backed prioritization signal, not a statement about your environment.
Analysis status
Analysis pending evidence review
Factual feed record only; HOL analysis is not approved for indexing. Read the methodology.
The current feed maps Linux/Linux (generic), Linux/Linux (generic), Siemens/SIMATIC S7-1500 CPU 1518-4 PN/DP MFP (generic), Siemens/SIMATIC S7-1500 CPU 1518F-4 PN/DP MFP (generic) and additional mapped packages. Check affected ranges and fixed versions before updating.
| Package | Affected range | Fixed version |
|---|---|---|
| Linux/Linuxgeneric | >=2fbc6e89b2f1403189e624cabaf73e189c5e50c6 <ce3c6165fce0f06305c806696882a3ad4b90e33f || >=2fbc6e89b2f1403189e624cabaf73e189c5e50c6 <ea07480b23225942208f1b754fea1e7ec486d37e || >=2fbc6e89b2f1403189e624cabaf73e189c5e50c6 <9b1766d1ff5fe496aabe9fc5f4e34e53f35c11c4 || >=2fbc6e89b2f1403189e624cabaf73e189c5e50c6 <4583748b65dee4d61bd50a2214715b4237bc152a || >=2fbc6e89b2f1403189e624cabaf73e189c5e50c6 <a39f61d212d822b3062d7f70fa0588e50e55664e || >=2fbc6e89b2f1403189e624cabaf73e189c5e50c6 <139512191bd06f1b496117c76372b2ce372c9a41 || f415c264176e6095e9dee823e09c5bdd0ee0d337 || 98776a365da509ad923083ae54b38ee521c52742 || 860e2cc78c697c95bc749abb20047239fa1722ea || 2b1be6c925cdf4638811765a9160796291494b89 || >=4.14.200 <4.15 || >=4.19.148 <4.20 || >=5.4.68 <5.5 || >=5.8.12 <5.9 | ce3c6165fce0f06305c806696882a3ad4b90e33f, ea07480b23225942208f1b754fea1e7ec486d37e, 9b1766d1ff5fe496aabe9fc5f4e34e53f35c11c4, 4583748b65dee4d61bd50a2214715b4237bc152a, a39f61d212d822b3062d7f70fa0588e50e55664e, 139512191bd06f1b496117c76372b2ce372c9a41, 4.15, 4.20, 5.5, 5.9 |
| Linux/Linuxgeneric | 5.9 | Not reported |
| Siemens/SIMATIC S7-1500 CPU 1518-4 PN/DP MFPgeneric | >=V3.1.5 <* | * |
| Siemens/SIMATIC S7-1500 CPU 1518F-4 PN/DP MFPgeneric | >=V3.1.5 <* | * |
| Siemens/SIPLUS S7-1500 CPU 1518-4 PN/DP MFPgeneric | >=V3.1.5 <* | * |
Published upstream
Feb 27, 2025
Evidence: source:cvelist:source_dates:source-dates:recordSource modified
Aug 5, 2026
Evidence: source:cvelist:source_dates:source-dates:recordFirst seen by HOL
Aug 5, 2026
In the Linux kernel, the following vulnerability has been resolved: ipv4: use RCU protection in __ip_rt_update_pmtu() __ip_rt_update_pmtu() must use RCU protection to make sure the net structure it reads does not disappear.
Quoted source text, attributed separately from HOL analysis.