THREAT OPS › Threat News › [NVD] CVE-2025-21720 (HIGH 7.5) — In the Linux kernel, the following vulnerability has been resolved:
xfrm: delete intermediate secpath entry in packet offload mode
Packets handled by hardware have added secpath as a way to inform XFRM
core code that this path was already handled. That secpath is not needed
at
[NVD] CVE-2025-21720 (HIGH 7.5) — In the Linux kernel, the following vulnerability has been resolved: xfrm: delete intermediate secpath entry in packet offload mode Packets handled by hardware have added secpath as a way to inform XFRM core code that this path was already handled. That secpath is not needed at
CVE-2025-21720 CVSS: 7.5 HIGH Published: 2025-02-27T02:15:15.683
In the Linux kernel, the following vulnerability has been resolved:
xfrm: delete intermediate secpath entry in packet offload mode
Packets handled by hardware have added secpath as a way to inform XFRM core code that this path was already handled. That secpath is not needed at all after policy is checked and it is removed later in
Indicators of compromise
- CVE-2025-21720cve
Original source: https://nvd.nist.gov/vuln/detail/CVE-2025-21720