CVE-2025-21629
CSIRTS triage
- What
- IPv6 checksum offload for BIG TCP packets was re-enabled to prevent denial of service.
- Who is affected
- Systems using IPv6 checksum offload with Big TCP packet handling.
- Urgency
- Moderately urgent as the issue can cause network availability problems.
- Action
- Apply the kernel patch that re-enables NETIF_F_IPV6_CSUM offload for BIG TCP packets.
AI-assisted analysis generated from the source advisory — verify against the original.
⚡ Watch CVE-2025-21629
Get an email if CVE-2025-21629 is added to CISA KEV, gains public exploit code, or a new advisory cites it — max one per day, one-click unsubscribe.
Exploitation outlook
- Low exploitation risk0.41% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 34% of all EPSS-scored CVEs.
Advisory coverage (1)
- mediumCVE-2025-21629: net: reenable NETIF_F_IPV6_CSUM offload for BIG TCP packetsmsrc · 2026-08-06
External references
Embed the live status
— this badge updates automatically when the KEV or exploit status changes. How to embed it →
[](https://www.csirts.com/cve/CVE-2025-21629)