Review reviewHigh

CVE-2025-21762

Linux Linux, SIMATIC S7-1500 TM MFP - BIOS, SIMATIC S7-1500 TM MFP - GNU/Linux subsystem

In the Linux kernel, the following vulnerability has been resolved: arp: use RCU protection in arp_xmit() arp_xmit() can be called without RTNL or RCU protection. Use RCU protection to avoid potential UAF.

CVSS
8.1
EPSS
0.61%
45.9% percentile
CISA KEV
Not listed
Published
2025.02.27
PRIORITY ASSESSMENT

Review review

The CVSS severity warrants an early asset and exposure review.

Known exploitationNot established by KEV
Exploit probability0.61%
Technical severityCVSS 8.1

Vulnerability overview

In the Linux kernel, the following vulnerability has been resolved: arp: use RCU protection in arp_xmit() arp_xmit() can be called without RTNL or RCU protection. Use RCU protection to avoid potential UAF.

Affected product and versions

Product
Linux Linux, SIMATIC S7-1500 TM MFP - BIOS, SIMATIC S7-1500 TM MFP - GNU/Linux subsystem
Affected versions
>= 29a26a56803855a79dbd028cd61abee56237d6e5 < 10f555e3f573d004ae9d89b3276abb58c4ede5c3, >= 29a26a56803855a79dbd028cd61abee56237d6e5 < 307cd1e2d3cb1cbc6c40c679cada6d7168b18431, >= 29a26a56803855a79dbd028cd61abee56237d6e5 < d9366ac2f956a1948b68c0500f84a3462ff2ed8a, >= 29a26a56803855a79dbd028cd61abee56237d6e5 < f189654459423d4d48bef2d120b4bfba559e6039, >= 29a26a56803855a79dbd028cd61abee56237d6e5 < e9f4dee534eb1b225b0a120395ad9bc2afe164d3, >= 29a26a56803855a79dbd028cd61abee56237d6e5 < 01d1b5c9abcaff29a43f1d17a19c33eec92c7dbe, >= 29a26a56803855a79dbd028cd61abee56237d6e5 < 2c331718d3389b6c5f6855078ab7171849e016bd, >= 29a26a56803855a79dbd028cd61abee56237d6e5 < a42b69f692165ec39db42d595f4f65a4c8f42e44, >= 4.4, >= 4.4 < 5.4.291, >= 5.5 < 5.10.235, >= 5.11 < 5.15.179, >= 5.16 < 6.1.129, >= 6.2 < 6.6.79, >= 6.7 < 6.12.16, >= 6.13 < 6.13.4, 6.14
Fixed versions
5.4.291, 5.10.235, 5.15.179, 6.1.129, 6.6.79, 6.12.16, 6.13.4

Recommended response sequence

Confirm exposure before applying a vendor-supported change.

Full remediation guide
  1. 1
    Identify

    Confirm that Linux Linux, SIMATIC S7-1500 TM MFP - BIOS, SIMATIC S7-1500 TM MFP - GNU/Linux subsystem and an affected version are present.

  2. 2
    Prioritize

    Combine exploitation signals with asset exposure and business criticality.

  3. 3
    Remediate

    Follow the vendor advisory or supported update path and preserve rollback options.

  4. 4
    Verify

    Recheck the version, service health, access paths, and relevant logs.

Technical data

CVSS vector
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
CWE
CWE-416