Review reviewHigh

CVE-2025-37913

Linux Linux, linux kernel, debian linux

In the Linux kernel, the following vulnerability has been resolved: net_sched: qfq: Fix double list add in class with netem as child qdisc As described in Gerrard's report [1], there are use cases where a netem child qdisc will make the parent qdisc's enqueue callback reentrant. In the case of qfq, there won't be a UAF, but the code will add the same classifier to the list twice, which will cause memory corruption. This patch checks whether the class was already added to the agg->active list (cl_is_active) before doing the addition to cater for the reentrant case. [1] https://lore.kernel.or...

CVSS
7.8
EPSS
0.18%
8.08% percentile
CISA KEV
Not listed
Published
2025.05.21
PRIORITY ASSESSMENT

Review review

The CVSS severity warrants an early asset and exposure review.

Known exploitationNot established by KEV
Exploit probability0.18%
Technical severityCVSS 7.8

Vulnerability overview

In the Linux kernel, the following vulnerability has been resolved: net_sched: qfq: Fix double list add in class with netem as child qdisc As described in Gerrard's report [1], there are use cases where a netem child qdisc will make the parent qdisc's enqueue callback reentrant. In the case of qfq, there won't be a UAF, but the code will add the same classifier to the list twice, which will cause memory corruption. This patch checks whether the class was already added to the agg->active list (cl_is_active) before doing the addition to cater for the reentrant case. [1] https://lore.kernel.or...

Affected product and versions

Product
Linux Linux, linux kernel, debian linux
Affected versions
>= 37d9cf1a3ce35de3df6f7d209bfb1f50cf188cea < 041f410aec2c1751ee22b8b73ba05d38c3a6a602, >= 37d9cf1a3ce35de3df6f7d209bfb1f50cf188cea < 005a479540478a820c52de098e5e767e63e36f0a, >= 37d9cf1a3ce35de3df6f7d209bfb1f50cf188cea < 0bf32d6fb1fcbf841bb9945570e0e2a70072c00f, >= 37d9cf1a3ce35de3df6f7d209bfb1f50cf188cea < 0aa23e0856b7cedb3c88d8e3d281c212c7e4fbeb, >= 37d9cf1a3ce35de3df6f7d209bfb1f50cf188cea < a43783119e01849fbf2fe8855634e8989b240cb4, >= 37d9cf1a3ce35de3df6f7d209bfb1f50cf188cea < 53bc0b55178bd59bdd4bcd16349505cabf54b1a2, >= 37d9cf1a3ce35de3df6f7d209bfb1f50cf188cea < 370218e8ce711684acc4cdd3cc3c6dd7956bc165, >= 37d9cf1a3ce35de3df6f7d209bfb1f50cf188cea < f139f37dcdf34b67f5bf92bc8e0f7f6b3ac63aa4, >= 5.0, >= 5.0.1 < 5.4.294, >= 5.5 < 5.10.238, >= 5.11 < 5.15.182, >= 5.16 < 6.1.138, >= 6.2 < 6.6.90, >= 6.7 < 6.12.28, >= 6.13 < 6.14.6, 5.0, 6.15, 11.0
Fixed versions
5.4.294, 5.10.238, 5.15.182, 6.1.138, 6.6.90, 6.12.28, 6.14.6

Recommended response sequence

Confirm exposure before applying a vendor-supported change.

Full remediation guide
  1. 1
    Identify

    Confirm that Linux Linux, linux kernel, debian linux and an affected version are present.

  2. 2
    Prioritize

    Combine exploitation signals with asset exposure and business criticality.

  3. 3
    Remediate

    Follow the vendor advisory or supported update path and preserve rollback options.

  4. 4
    Verify

    Recheck the version, service health, access paths, and relevant logs.

Technical data

CVSS vector
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
CWE
CWE-415