CVE-2025-21678 | Linux Kernel up to 5.15.176/6.1.126/6.6.73/6.12.10 drivers/net/gtp.c gtp_newlink iteration (Nessus ID 215144 / WID-SEC-2025-0232)
A vulnerability categorized as problematic has been discovered in Linux Kernel up to 5.15.176/6.1.126/6.6.73/6.12.10. Affected is the function gtp_newlink in the library lib/ref_tracker.c of the file drivers/net/gtp.c. Such manipulation leads to excessive iteration.
This vulnerability is referenced as CVE-2025-21678. The attack needs to be initiated within the local network. No exploit is available.
It is advisable to upgrade the affected component.