Review reviewHigh

CVE-2025-37798

Linux Linux, linux kernel, debian linux

In the Linux kernel, the following vulnerability has been resolved: codel: remove sch->q.qlen check before qdisc_tree_reduce_backlog() After making all ->qlen_notify() callbacks idempotent, now it is safe to remove the check of qlen!=0 from both fq_codel_dequeue() and codel_qdisc_dequeue().

CVSS
7.8
EPSS
0.20%
9.99% percentile
CISA KEV
Not listed
Published
2025.05.03
PRIORITY ASSESSMENT

Review review

The CVSS severity warrants an early asset and exposure review.

Known exploitationNot established by KEV
Exploit probability0.20%
Technical severityCVSS 7.8

Vulnerability overview

In the Linux kernel, the following vulnerability has been resolved: codel: remove sch->q.qlen check before qdisc_tree_reduce_backlog() After making all ->qlen_notify() callbacks idempotent, now it is safe to remove the check of qlen!=0 from both fq_codel_dequeue() and codel_qdisc_dequeue().

Affected product and versions

Product
Linux Linux, linux kernel, debian linux
Affected versions
>= 76e3cc126bb223013a6b9a0e2a51238d1ef2e409 < 7a742a9506849d1c1aa71e36c89855ceddc7d58e, >= 76e3cc126bb223013a6b9a0e2a51238d1ef2e409 < cc71a757da78dd4aa1b4a9b19cb011833730ccf2, >= 76e3cc126bb223013a6b9a0e2a51238d1ef2e409 < eda741fe155ddf5ecd2dd3bfbd4fc3c0c7dbb450, >= 76e3cc126bb223013a6b9a0e2a51238d1ef2e409 < 829c49b6b2ff45b043739168fd1245e4e1a91a30, >= 76e3cc126bb223013a6b9a0e2a51238d1ef2e409 < 2f9761a94bae33d26e6a81b31b36e7d776d93dc1, >= 76e3cc126bb223013a6b9a0e2a51238d1ef2e409 < 4d55144b12e742404bb3f8fee6038bafbf45619d, >= 76e3cc126bb223013a6b9a0e2a51238d1ef2e409 < e73c838c80dccb9e4f19becc11d9f3cb4a27d483, >= 76e3cc126bb223013a6b9a0e2a51238d1ef2e409 < a57fe60ef4cf96bfbb6b58397ec28bdb5a5c6b31, >= 76e3cc126bb223013a6b9a0e2a51238d1ef2e409 < 342debc12183b51773b3345ba267e9263bdfaaef, >= 3.5, >= 3.5 < 5.4.297, >= 5.5 < 5.10.241, >= 5.11 < 5.15.190, >= 5.16 < 6.1.135, >= 6.2 < 6.6.88, >= 6.7 < 6.12.24, >= 6.13 < 6.13.12, >= 6.14 < 6.14.3, 6.15, 11.0
Fixed versions
5.4.297, 5.10.241, 5.15.190, 6.1.135, 6.6.88, 6.12.24, 6.13.12, 6.14.3

Recommended response sequence

Confirm exposure before applying a vendor-supported change.

Full remediation guide
  1. 1
    Identify

    Confirm that Linux Linux, linux kernel, debian linux and an affected version are present.

  2. 2
    Prioritize

    Combine exploitation signals with asset exposure and business criticality.

  3. 3
    Remediate

    Follow the vendor advisory or supported update path and preserve rollback options.

  4. 4
    Verify

    Recheck the version, service health, access paths, and relevant logs.

Technical data

CVSS vector
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
CWE
Not available