Review reviewHigh

CVE-2025-38087

Linux Linux, linux kernel

In the Linux kernel, the following vulnerability has been resolved: net/sched: fix use-after-free in taprio_dev_notifier Since taprio’s taprio_dev_notifier() isn’t protected by an RCU read-side critical section, a race with advance_sched() can lead to a use-after-free. Adding rcu_read_lock() inside taprio_dev_notifier() prevents this.

CVSS
7.8
EPSS
0.15%
4.44% percentile
CISA KEV
Not listed
Published
2025.06.30
PRIORITY ASSESSMENT

Review review

The CVSS severity warrants an early asset and exposure review.

Known exploitationNot established by KEV
Exploit probability0.15%
Technical severityCVSS 7.8

Vulnerability overview

In the Linux kernel, the following vulnerability has been resolved: net/sched: fix use-after-free in taprio_dev_notifier Since taprio’s taprio_dev_notifier() isn’t protected by an RCU read-side critical section, a race with advance_sched() can lead to a use-after-free. Adding rcu_read_lock() inside taprio_dev_notifier() prevents this.

Affected product and versions

Product
Linux Linux, linux kernel
Affected versions
>= fed87cc6718ad5f80aa739fee3c5979a8b09d3a6 < 8c5713ce1ced75f9e9ed5c642ea3d2ba06ead69c, >= fed87cc6718ad5f80aa739fee3c5979a8b09d3a6 < 8a008c89e5e5c5332e4c0a33d707db9ddd529f8a, >= fed87cc6718ad5f80aa739fee3c5979a8b09d3a6 < b1547d28ba468bc3b88764efd13e4319bab63be8, >= fed87cc6718ad5f80aa739fee3c5979a8b09d3a6 < b160766e26d4e2e2d6fe2294e0b02f92baefcec5, >= 6.3, >= 6.3 < 6.6.95, >= 6.7 < 6.12.35, >= 6.13 < 6.15.4, 6.16
Fixed versions
6.6.95, 6.12.35, 6.15.4

Recommended response sequence

Confirm exposure before applying a vendor-supported change.

Full remediation guide
  1. 1
    Identify

    Confirm that Linux Linux, linux kernel and an affected version are present.

  2. 2
    Prioritize

    Combine exploitation signals with asset exposure and business criticality.

  3. 3
    Remediate

    Follow the vendor advisory or supported update path and preserve rollback options.

  4. 4
    Verify

    Recheck the version, service health, access paths, and relevant logs.

Technical data

CVSS vector
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
CWE
CWE-416
CVE-2025-38087 — Linux Linux, linux kernel | SECUFOCUS NOW