{"schema_version":"1.7.5","id":"CVE-2025-38550","published":"2025-08-16T11:34:18.619Z","modified":"2026-07-25T04:14:39.489452115Z","related":["ALSA-2025:15740","ALSA-2025:15782","SUSE-SU-2025:03272-1","SUSE-SU-2025:03290-1","SUSE-SU-2025:03301-1","SUSE-SU-2025:03382-1","SUSE-SU-2025:03602-1","SUSE-SU-2025:03633-1","SUSE-SU-2025:03634-1","SUSE-SU-2025:20653-1","SUSE-SU-2025:20669-1","SUSE-SU-2025:20739-1","SUSE-SU-2025:20756-1","SUSE-SU-2026:20555-1","SUSE-SU-2026:20570-1","SUSE-SU-2026:20599-1","SUSE-SU-2026:20615-1","openSUSE-SU-2026:20287-1"],"summary":"ipv6: mcast: Delay put pmc->idev in mld_del_delrec()","details":"In the Linux kernel, the following vulnerability has been resolved:\n\nipv6: mcast: Delay put pmc->idev in mld_del_delrec()\n\npmc->idev is still used in ip6_mc_clear_src(), so as mld_clear_delrec()\ndoes, the reference should be put after ip6_mc_clear_src() return.","affected":[{"ranges":[{"type":"GIT","repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","events":[{"introduced":"b564ec4491d24b40900c64ab9e29a208f17f3108"},{"fixed":"1b5b413094af8d88a31b5df3fd262f6baca53841"}]},{"type":"GIT","repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","events":[{"introduced":"63ed8de4be81b699ca727e9f8e3344bd487806d7"},{"fixed":"6e4eec86fe5f6b3fdbc702d1d36ac2a6e7ec0806"},{"fixed":"728db00a14cacb37f36e9382ab5fad55caf890cc"},{"fixed":"dcbc346f50a009d8b7f4e330f9f2e22d6442fa26"},{"fixed":"7929d27c747eafe8fca3eecd74a334503ee4c839"},{"fixed":"5f18e0130194550dff734e155029ae734378b5ea"},{"fixed":"ae3264a25a4635531264728859dbe9c659fad554"}]}],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2025-38550.json"}},{"package":{"name":"Kernel","ecosystem":"Linux"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"5.13.0"},{"fixed":"5.15.190"}]},{"type":"ECOSYSTEM","events":[{"introduced":"5.16.0"},{"fixed":"6.1.147"}]},{"type":"ECOSYSTEM","events":[{"introduced":"6.2.0"},{"fixed":"6.6.100"}]},{"type":"ECOSYSTEM","events":[{"introduced":"6.7.0"},{"fixed":"6.12.40"}]},{"type":"ECOSYSTEM","events":[{"introduced":"6.13.0"},{"fixed":"6.15.8"}]}],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2025-38550.json"}}],"references":[{"type":"WEB","url":"https://git.kernel.org/stable/c/1b5b413094af8d88a31b5df3fd262f6baca53841"},{"type":"WEB","url":"https://git.kernel.org/stable/c/5f18e0130194550dff734e155029ae734378b5ea"},{"type":"WEB","url":"https://git.kernel.org/stable/c/6e4eec86fe5f6b3fdbc702d1d36ac2a6e7ec0806"},{"type":"WEB","url":"https://git.kernel.org/stable/c/728db00a14cacb37f36e9382ab5fad55caf890cc"},{"type":"WEB","url":"https://git.kernel.org/stable/c/7929d27c747eafe8fca3eecd74a334503ee4c839"},{"type":"WEB","url":"https://git.kernel.org/stable/c/ae3264a25a4635531264728859dbe9c659fad554"},{"type":"WEB","url":"https://git.kernel.org/stable/c/dcbc346f50a009d8b7f4e330f9f2e22d6442fa26"},{"type":"WEB","url":"https://lists.debian.org/debian-lts-announce/2025/10/msg00008.html"},{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2025/38xxx/CVE-2025-38550.json"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2025-38550"},{"type":"PACKAGE","url":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git"}],"database_specific":{"cna_assigner":"Linux","osv_generated_from":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2025/38xxx/CVE-2025-38550.json"}}