Review reviewHigh

CVE-2025-38108

Linux Linux, linux kernel, debian linux

In the Linux kernel, the following vulnerability has been resolved: net_sched: red: fix a race in __red_change() Gerrard Tai reported a race condition in RED, whenever SFQ perturb timer fires at the wrong time. The race is as follows: CPU 0 CPU 1 [1]: lock root [2]: qdisc_tree_flush_backlog() [3]: unlock root | | [5]: lock root | [6]: rehash | [7]: qdisc_tree_reduce_backlog() | [4]: qdisc_put() This can be abused to underflow a parent's qlen. Calling qdisc_purge_queue() instead of qdisc_tree_flush_backlog() should fix the race, because all packets will be purged from the qdisc before releas...

CVSS
7
EPSS
0.13%
3.26% percentile
CISA KEV
Not listed
Published
2025.07.03
PRIORITY ASSESSMENT

Review review

The CVSS severity warrants an early asset and exposure review.

Known exploitationNot established by KEV
Exploit probability0.13%
Technical severityCVSS 7

Vulnerability overview

In the Linux kernel, the following vulnerability has been resolved: net_sched: red: fix a race in __red_change() Gerrard Tai reported a race condition in RED, whenever SFQ perturb timer fires at the wrong time. The race is as follows: CPU 0 CPU 1 [1]: lock root [2]: qdisc_tree_flush_backlog() [3]: unlock root | | [5]: lock root | [6]: rehash | [7]: qdisc_tree_reduce_backlog() | [4]: qdisc_put() This can be abused to underflow a parent's qlen. Calling qdisc_purge_queue() instead of qdisc_tree_flush_backlog() should fix the race, because all packets will be purged from the qdisc before releas...

Affected product and versions

Product
Linux Linux, linux kernel, debian linux
Affected versions
>= 0c8d13ac96070000da33f394f45e9c19638483c5 < 2790c4ec481be45a80948d059cd7c9a06bc37493, >= 0c8d13ac96070000da33f394f45e9c19638483c5 < a1bf6a4e9264a685b0e642994031f9c5aad72414, >= 0c8d13ac96070000da33f394f45e9c19638483c5 < 110a47efcf23438ff8d31dbd9c854fae2a48bf98, >= 0c8d13ac96070000da33f394f45e9c19638483c5 < f569984417a4e12c67366e69bdcb752970de921d, >= 0c8d13ac96070000da33f394f45e9c19638483c5 < 2a71924ca4af59ffc00f0444732b6cd54b153d0e, >= 0c8d13ac96070000da33f394f45e9c19638483c5 < 4b755305b2b0618e857fdadb499365b5f2e478d1, >= 0c8d13ac96070000da33f394f45e9c19638483c5 < 444ad445df5496a785705019268a8a84b84484bb, >= 0c8d13ac96070000da33f394f45e9c19638483c5 < 85a3e0ede38450ea3053b8c45d28cf55208409b8, >= 5.0, >= 5.0 < 5.4.295, >= 5.5 < 5.10.239, >= 5.11 < 5.15.186, >= 5.16 < 6.1.142, >= 6.2 < 6.6.94, >= 6.7 < 6.12.34, >= 6.13 < 6.15.3, 6.16, 11.0
Fixed versions
5.4.295, 5.10.239, 5.15.186, 6.1.142, 6.6.94, 6.12.34, 6.15.3

Recommended response sequence

Confirm exposure before applying a vendor-supported change.

Full remediation guide
  1. 1
    Identify

    Confirm that Linux Linux, linux kernel, debian linux and an affected version are present.

  2. 2
    Prioritize

    Combine exploitation signals with asset exposure and business criticality.

  3. 3
    Remediate

    Follow the vendor advisory or supported update path and preserve rollback options.

  4. 4
    Verify

    Recheck the version, service health, access paths, and relevant logs.

Technical data

CVSS vector
CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H
CWE
CWE-362