CVE-2025-21864 is an improper resource-release flaw in the Linux kernel TCP receive path. When TCP processing discards an skb destination reference but retains the skb security path, the retained secpath can continue holding a reference to an XFRM state. If skb freeing is deferred on a CPU list and the associated network namespace is deleted before that list is flushed, the XFRM state remains referenced unexpectedly during namespace teardown, resulting in a warning from the IPv6 XFRM tunnel teardown path. The fix releases secpath at the same point TCP releases the destination reference, after LSM processing no longer requires the security-path metadata, while retaining unrelated skb extensions such as MPTCP metadata.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
No public exploits tracked yet. Mallory keeps watching.
No public exploit code observed for this vulnerability.
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
2 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Linux kernel TCP security-path resource-lifetime flaw.
A Linux kernel TCP/IPsec (XFRM) lifecycle flaw in which a secpath retained on a deferred-freed socket buffer can keep a reference to an xfrm_state beyond network-namespace deletion, triggering a WARN in xfrm6_tunnel_net_exit. The fix drops the secpath in the TCP receive path when the destination is dropped.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.