Answer in brief
CVE-2025-38550 records a Unknown severity vulnerability in ipv6: mcast: Delay put pmc->idev in mld_del_delrec(). The current sources do not mark it as known exploited. The current feed maps Linux/Linux (generic), Linux/Linux (generic). Check affected ranges and fixed versions before updating.
Analysis pending evidence review
HOL Guard separates source facts from reviewed analysis. See the methodology.
Answer in brief
CVE-2025-38550 records a Unknown severity vulnerability in ipv6: mcast: Delay put pmc->idev in mld_del_delrec(). The current sources do not mark it as known exploited. The current feed maps Linux/Linux (generic), Linux/Linux (generic). Check affected ranges and fixed versions before updating.
Analysis pending evidence review
HOL Guard separates source facts from reviewed analysis. See the methodology.
A CVSS score is not reported in the current record. The current sources do not mark it as known exploited. Treat this as a source-backed prioritization signal, not a statement about your environment.
Analysis status
Analysis pending evidence review
Factual feed record only; HOL analysis is not approved for indexing. Read the methodology.
The current feed maps Linux/Linux (generic), Linux/Linux (generic). Check affected ranges and fixed versions before updating.
| Package | Affected range | Fixed version |
|---|---|---|
| Linux/Linuxgeneric | >=b564ec4491d24b40900c64ab9e29a208f17f3108 <1b5b413094af8d88a31b5df3fd262f6baca53841 || >=63ed8de4be81b699ca727e9f8e3344bd487806d7 <6e4eec86fe5f6b3fdbc702d1d36ac2a6e7ec0806 || >=63ed8de4be81b699ca727e9f8e3344bd487806d7 <728db00a14cacb37f36e9382ab5fad55caf890cc || >=63ed8de4be81b699ca727e9f8e3344bd487806d7 <dcbc346f50a009d8b7f4e330f9f2e22d6442fa26 || >=63ed8de4be81b699ca727e9f8e3344bd487806d7 <7929d27c747eafe8fca3eecd74a334503ee4c839 || >=63ed8de4be81b699ca727e9f8e3344bd487806d7 <5f18e0130194550dff734e155029ae734378b5ea || >=63ed8de4be81b699ca727e9f8e3344bd487806d7 <ae3264a25a4635531264728859dbe9c659fad554 | 1b5b413094af8d88a31b5df3fd262f6baca53841, 6e4eec86fe5f6b3fdbc702d1d36ac2a6e7ec0806, 728db00a14cacb37f36e9382ab5fad55caf890cc, dcbc346f50a009d8b7f4e330f9f2e22d6442fa26, 7929d27c747eafe8fca3eecd74a334503ee4c839, 5f18e0130194550dff734e155029ae734378b5ea, ae3264a25a4635531264728859dbe9c659fad554 |
| Linux/Linuxgeneric | 5.13 | Not reported |
Published upstream
Aug 16, 2025
Evidence: source:cvelist:source_dates:source-dates:recordSource modified
Aug 5, 2026
Evidence: source:cvelist:source_dates:source-dates:recordFirst seen by HOL
Aug 5, 2026
In the Linux kernel, the following vulnerability has been resolved: ipv6: mcast: Delay put pmc->idev in mld_del_delrec() pmc->idev is still used in ip6_mc_clear_src(), so as mld_clear_delrec() does, the reference should be put after ip6_mc_clear_src() return.
Quoted source text, attributed separately from HOL analysis.
A CVSS score is not reported in the current record. The current sources do not mark it as known exploited. Treat this as a source-backed prioritization signal, not a statement about your environment.
Analysis status
Analysis pending evidence review
Factual feed record only; HOL analysis is not approved for indexing. Read the methodology.
The current feed maps Linux/Linux (generic), Linux/Linux (generic). Check affected ranges and fixed versions before updating.
| Package | Affected range | Fixed version |
|---|---|---|
| Linux/Linuxgeneric | >=b564ec4491d24b40900c64ab9e29a208f17f3108 <1b5b413094af8d88a31b5df3fd262f6baca53841 || >=63ed8de4be81b699ca727e9f8e3344bd487806d7 <6e4eec86fe5f6b3fdbc702d1d36ac2a6e7ec0806 || >=63ed8de4be81b699ca727e9f8e3344bd487806d7 <728db00a14cacb37f36e9382ab5fad55caf890cc || >=63ed8de4be81b699ca727e9f8e3344bd487806d7 <dcbc346f50a009d8b7f4e330f9f2e22d6442fa26 || >=63ed8de4be81b699ca727e9f8e3344bd487806d7 <7929d27c747eafe8fca3eecd74a334503ee4c839 || >=63ed8de4be81b699ca727e9f8e3344bd487806d7 <5f18e0130194550dff734e155029ae734378b5ea || >=63ed8de4be81b699ca727e9f8e3344bd487806d7 <ae3264a25a4635531264728859dbe9c659fad554 | 1b5b413094af8d88a31b5df3fd262f6baca53841, 6e4eec86fe5f6b3fdbc702d1d36ac2a6e7ec0806, 728db00a14cacb37f36e9382ab5fad55caf890cc, dcbc346f50a009d8b7f4e330f9f2e22d6442fa26, 7929d27c747eafe8fca3eecd74a334503ee4c839, 5f18e0130194550dff734e155029ae734378b5ea, ae3264a25a4635531264728859dbe9c659fad554 |
| Linux/Linuxgeneric | 5.13 | Not reported |
Published upstream
Aug 16, 2025
Evidence: source:cvelist:source_dates:source-dates:recordSource modified
Aug 5, 2026
Evidence: source:cvelist:source_dates:source-dates:recordFirst seen by HOL
Aug 5, 2026
In the Linux kernel, the following vulnerability has been resolved: ipv6: mcast: Delay put pmc->idev in mld_del_delrec() pmc->idev is still used in ip6_mc_clear_src(), so as mld_clear_delrec() does, the reference should be put after ip6_mc_clear_src() return.
Quoted source text, attributed separately from HOL analysis.