You are using an out of date browser. It may not display this or other websites correctly. You should upgrade or use an alternative browser.
cve 2025 38476
About this tag
CVE-2025-38476 is a Linux kernel vulnerability in the IPv6 route-probing/lwtunnel code that can lead to a use-after-free condition detectable under KASAN testing. The flaw is addressed by an upstream patch described as 'rpl: Fix use-after-free in rpl_do_srh_inline'. Microsoft's Security Response Center (MSRC) has published an attestation stating that Azure Linux includes the implicated open-source component and is therefore potentially affected. Microsoft has also committed to expanding its machine-readable CSAF/VEX attestations as it inventories additional product artifacts. This tag covers discussions about the vulnerability, the patch, and Microsoft's response for Azure Linux users.
A recent upstream Linux kernel fix — recorded as CVE-2025-38476 and described in the patch notes as “rpl: Fix use-after-free in rpl_do_srh_inline” — addresses a correctness bug in the kernel’s IPv6 route-probing/lwtunnel code that can lead to a use‑after‑free detectable under KASAN testing...