🛡️ AZL-60331 — kernel (CVE-2025-21891)

⚪ Unknown ✅ No Known Exploit OSV
N/A
CVSS Score
0 Low4 Medium7 High9 Critical10

Description

CVE-2025-21891 affecting package kernel 5.15.200.1-1

In the Linux kernel, the following vulnerability has been resolved:

ipvlan: ensure network headers are in skb linear part

syzbot found that ipvlan_process_v6_outbound() was assuming

the IPv6 network header isis present in skb->head [1]

Add the needed pskb_network_may_pull() calls for both

IPv4 and IPv6 handlers.

[1]

BUG: KMSAN: uninit-value in __ipv6_addr_type+0xa2/0x490 net/ipv6/addrconf_core.c:47

__ipv6_addr_type+0xa2/0x490 net/ipv6/addrconf_core.c:47

ipv6_addr_type include/net/ipv6.h:555 [inline]

ip6_route_output_flags_noref net/ipv6/route.c:2616 [inline]

ip6_route_output_flags+0x51/0x720 net/ipv6/route.c:2651

ip6_route_output include/net/ip6_route.h:93 [inline]

ipvlan_route_v6_outbound+0x24e/0x520 drivers/net/ipvlan/ipvlan_core.c:476

ipvlan_process_v6_outbound drivers/net/ipvlan/ipvlan_core.c:491 [inline]

ipvlan_process_outbound drivers/net/ipvlan/ipvlan_core.c:541 [inline]

ipvlan_xmit_mode_l3 drivers/net/ipvlan/ipvlan_core.c:605 [inline]

ipvlan_queue_xmit+0xd72/0x1780 drivers/net/ipvlan/ipvlan_core.c:671

ipvlan_start_xmit+0x5b/0x210 drivers/net/ipvlan/ipvlan_main.c:223

__netdev_start_xmit include/linux/netdevice.h:5150 [inline]

netdev_start_xmit include/linux/netdevice.h:5159 [inline]

xmit_one net/core/dev.c:3735 [inline]

dev_hard_start_xmit+0x247/0xa20 net/core/dev.c:3751

sch_direct_xmit+0x399/0xd40 net/sched/sch_generic.c:343

qdisc_restart net/sched/sch_generic.c:408 [inline]

__qdisc_run+0x14da/0x35d0 net/sched/sch_generic.c:416

qdisc_run+0x141/0x4d0 include/net/pkt_sched.h:127

net_tx_action+0x78b/0x940 net/core/dev.c:5484

handle_softirqs+0x1a0/0x7c0 kernel/softirq.c:561

__do_softirq+0x14/0x1a kernel/softirq.c:595

do_softirq+0x9a/0x100 kernel/softirq.c:462

__local_bh_enable_ip+0x9f/0xb0 kernel/softirq.c:389

local_bh_enable include/linux/bottom_half.h:33 [inline]

rcu_read_unlock_bh include/linux/rcupdate.h:919 [inline]

__dev_queue_xmit+0x2758/0x57d0 net/core/dev.c:4611

dev_queue_xmit include/linux/netdevice.h:3311 [inline]

packet_xmit+0x9c/0x6c0 net/packet/af_packet.c:276

packet_snd net/packet/af_packet.c:3132 [inline]

packet_sendmsg+0x93e0/0xa7e0 net/packet/af_packet.c:3164

sock_sendmsg_nosec net/socket.c:718 [inline]

How this vulnerability can be exploited

This issue can be reached with local access to the system, attack complexity is low, an attacker needs low-level privileges on the target. No user interaction is required. The scope is unchanged, so the impact stays within the vulnerable component. Rated impact: confidentiality none, integrity none, availability high.

Affected software

AZL-60331 is recorded against 1 package.

  • kernel

Timeline and source

Published on 27 March 2025 and last revised on 21 April 2026. No public exploit is currently recorded for this entry. Record sourced from OSV.

References

nvd.nist.gov (Web)

Details

Severity Unknown
CVSS Score N/A
CVSS Vector CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
CWE N/A
Public Exploit ✅ No
Source OSV
Published 2025-03-27
Updated 2026-08-12
Modified 2026-04-21
Fix URL N/A

Affected Packages

Software From version Fixed in
kernel

Similar Threats

Free Vulnerability Check

Is your site affected by AZL-60331?

BotEraser helps you identify potentially vulnerable plugins and themes by checking your installation against AZL-60331 and other known CVE records.

Scan My Site Free →

No credit card required  ·  Results in minutes

ⓘ Data Notice: The information presented above has been compiled from publicly available internet sources. Boteraser aggregates this data solely for informational purposes and does not independently classify, evaluate, or endorse any findings about the vulnerabilities listed. The accuracy and completeness of this information is the sole responsibility of the original publishers. Boteraser and its operators accept no liability for any decisions made based on this data.

Browse related advisories

All advisoriesAzure LinuxAzure Linux Undated