net/sched: sch_qfq: Fix race condition on qfq_aggregate
Summary
| CVE | CVE-2025-38477 |
|---|---|
| State | PUBLISHED |
| Assigner | Linux |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2025-07-28 12:15:29 UTC |
| Updated | 2026-05-12 13:16:51 UTC |
| Description | In the Linux kernel, the following vulnerability has been resolved: net/sched: sch_qfq: Fix race condition on qfq_aggregate A race condition can occur when 'agg' is modified in qfq_change_agg (called during qfq_enqueue) while other threads access it concurrently. For example, qfq_dump_class may trigger a NULL dereference, and qfq_delete_class may cause a use-after-free. This patch addresses the issue by: 1. Moved qfq_destroy_class into the critical section. 2. Added sch_tree_lock protection to qfq_dump_class and qfq_dump_class_stats. |
Risk And Classification
Primary CVSS: v3.1 4.7 MEDIUM from [email protected]
CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H
Problem Types: CWE-362
CVSS v3.1 Breakdown
Attack Vector
LocalAttack Complexity
HighPrivileges Required
LowUser Interaction
NoneScope
UnchangedConfidentiality
NoneIntegrity
NoneAvailability
HighCVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Operating System | Linux | Linux Kernel | All | All | All | All |
Vendor Declared Affected Products
| Source | Vendor | Product | Version | Platforms |
|---|---|---|---|---|
| CNA | Linux | Linux | affected 462dbc9101acd38e92eda93c0726857517a24bbd aa7a22c4d678bf649fd3a1d27debec583563414d git | Not specified |
| CNA | Linux | Linux | affected 462dbc9101acd38e92eda93c0726857517a24bbd d841aa5518508ab195b6781ad0d73ee378d713dd git | Not specified |
| CNA | Linux | Linux | affected 462dbc9101acd38e92eda93c0726857517a24bbd c6df794000147a3a02f79984aada4ce83f8d0a1e git | Not specified |
| CNA | Linux | Linux | affected 462dbc9101acd38e92eda93c0726857517a24bbd 466e10194ab81caa2ee6a332d33ba16bcceeeba6 git | Not specified |
| CNA | Linux | Linux | affected 462dbc9101acd38e92eda93c0726857517a24bbd fbe48f06e64134dfeafa89ad23387f66ebca3527 git | Not specified |
| CNA | Linux | Linux | affected 462dbc9101acd38e92eda93c0726857517a24bbd a6d735100f602c830c16d69fb6d780eebd8c9ae1 git | Not specified |
| CNA | Linux | Linux | affected 462dbc9101acd38e92eda93c0726857517a24bbd c000a3a330d97f6c073ace5aa5faf94b9adb4b79 git | Not specified |
| CNA | Linux | Linux | affected 462dbc9101acd38e92eda93c0726857517a24bbd 5e28d5a3f774f118896aec17a3a20a9c5c9dfc64 git | Not specified |
| CNA | Linux | Linux | affected 3.8 | Not specified |
| CNA | Linux | Linux | unaffected 3.8 semver | Not specified |
| CNA | Linux | Linux | unaffected 5.4.297 5.4.* semver | Not specified |
| CNA | Linux | Linux | unaffected 5.10.241 5.10.* semver | Not specified |
| CNA | Linux | Linux | unaffected 5.15.190 5.15.* semver | Not specified |
| CNA | Linux | Linux | unaffected 6.1.147 6.1.* semver | Not specified |
| CNA | Linux | Linux | unaffected 6.6.100 6.6.* semver | Not specified |
| CNA | Linux | Linux | unaffected 6.12.40 6.12.* semver | Not specified |
| CNA | Linux | Linux | unaffected 6.15.8 6.15.* semver | Not specified |
| CNA | Linux | Linux | unaffected 6.16 * original_commit_for_fix | Not specified |
| ADP | Siemens | SIMATIC S7-1500 CPU 1518-4 PN/DP MFP | affected V3.1.5 * custom | Not specified |
| ADP | Siemens | SIMATIC S7-1500 CPU 1518-4 PN/DP MFP | affected V3.1.5 * custom | Not specified |
| ADP | Siemens | SIMATIC S7-1500 CPU 1518F-4 PN/DP MFP | affected V3.1.5 * custom | Not specified |
| ADP | Siemens | SIMATIC S7-1500 CPU 1518F-4 PN/DP MFP | affected V3.1.5 * custom | Not specified |
| ADP | Siemens | SIPLUS S7-1500 CPU 1518-4 PN/DP MFP | affected V3.1.5 * custom | Not specified |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| git.kernel.org/stable/c/466e10194ab81caa2ee6a332d33ba16bcceeeba6 | 416baaa9-dc9f-4396-8d5f-8c081fb06d67 | git.kernel.org | Patch |
| git.kernel.org/stable/c/fbe48f06e64134dfeafa89ad23387f66ebca3527 | 416baaa9-dc9f-4396-8d5f-8c081fb06d67 | git.kernel.org | Patch |
| lists.debian.org/debian-lts-announce/2025/10/msg00008.html | af854a3a-2127-422b-91ae-364da2661108 | lists.debian.org | Mailing List, Third Party Advisory |
| cert-portal.siemens.com/productcert/html/ssa-082556.html | 0b142b55-0307-4c5a-b3c9-f314f3fb7c5e | cert-portal.siemens.com | |
| git.kernel.org/stable/c/c6df794000147a3a02f79984aada4ce83f8d0a1e | 416baaa9-dc9f-4396-8d5f-8c081fb06d67 | git.kernel.org | Patch |
| git.kernel.org/stable/c/5e28d5a3f774f118896aec17a3a20a9c5c9dfc64 | 416baaa9-dc9f-4396-8d5f-8c081fb06d67 | git.kernel.org | Patch |
| git.kernel.org/stable/c/aa7a22c4d678bf649fd3a1d27debec583563414d | 416baaa9-dc9f-4396-8d5f-8c081fb06d67 | git.kernel.org | Patch |
| git.kernel.org/stable/c/c000a3a330d97f6c073ace5aa5faf94b9adb4b79 | 416baaa9-dc9f-4396-8d5f-8c081fb06d67 | git.kernel.org | Patch |
| git.kernel.org/stable/c/d841aa5518508ab195b6781ad0d73ee378d713dd | 416baaa9-dc9f-4396-8d5f-8c081fb06d67 | git.kernel.org | Patch |
| git.kernel.org/stable/c/a6d735100f602c830c16d69fb6d780eebd8c9ae1 | 416baaa9-dc9f-4396-8d5f-8c081fb06d67 | git.kernel.org | Patch |
| lists.debian.org/debian-lts-announce/2025/10/msg00007.html | af854a3a-2127-422b-91ae-364da2661108 | lists.debian.org | Mailing List, Third Party Advisory |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.