CVE-2025-38083

MEDIUM EPSS 1.6%
Published Jun 20, 20251y ago · Modified Jun 17, 20261w ago
4.7 CVSS 3.1
Medium
Find Similar
Published Jun 20, 2025 1y ago
Last Modified Jun 17, 2026 1w ago

Description

In the Linux kernel, the following vulnerability has been resolved: net_sched: prio: fix a race in prio_tune() Gerrard Tai reported a race condition in PRIO, whenever SFQ perturb timer fires at the wrong time. The race is as follows: CPU 0 CPU 1 [1]: lock root [2]: qdisc_tree_flush_backlog() [3]: unlock root | | [5]: lock root | [6]: rehash | [7]: qdisc_tree_reduce_backlog() | [4]: qdisc_put() This can be abused to underflow a parent's qlen. Calling qdisc_purge_queue() instead of qdisc_tree_flush_backlog() should fix the race, because all packets will be purged from the qdisc before releasing the lock.

CVSS Details

Base Score
4.7
Exploitability
1.0
Impact
3.6
Vector string
CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H
Attack Vector Local
Attack Complexity High
Privileges Required Low
User Interaction None
Scope Unchanged
Confidentiality None
Integrity None
Availability High

Threat Intelligence

EPSS Exploit Probability
1.6% percentile
Exploit & Patch Status
No Known Exploit
Patch Available

Weaknesses 1

CWE-362

Affected Products 9

VendorProductVersionRange
linuxlinux_kernel*≥5.0  –  <5.4.295
linuxlinux_kernel*≥5.5  –  <5.10.239
linuxlinux_kernel*≥5.11  –  <5.15.186
linuxlinux_kernel*≥5.16  –  <6.1.142
linuxlinux_kernel*≥6.2  –  <6.6.94
linuxlinux_kernel*≥6.7  –  <6.12.34
linuxlinux_kernel*≥6.13  –  <6.15.3
linuxlinux_kernel6.16any
debiandebian_linux11.0any

References 11

  • cert-portal.siemens.com https://cert-portal.siemens.com/productcert/html/ssa-082556.html
  • git.kernel.org https://git.kernel.org/stable/c/20f68e6a9e41693cb0e55e5b9ebbcb40983a4b8f
    Patch
  • git.kernel.org https://git.kernel.org/stable/c/3aaa7c01cf19d9b9bb64b88b65c3a6fd05da2eb4
    Patch
  • git.kernel.org https://git.kernel.org/stable/c/4483d8b9127591c60c4eb789d6cab953bc4522a9
    Patch
  • git.kernel.org https://git.kernel.org/stable/c/46c15c9d0f65c9ba857d63f53264f4b17e8a715f
    Patch
  • git.kernel.org https://git.kernel.org/stable/c/53d11560e957d53ee87a0653d258038ce12361b7
    Patch
  • git.kernel.org https://git.kernel.org/stable/c/93f9eeb678d4c9c1abf720b3615fa8299a490845
    Patch
  • git.kernel.org https://git.kernel.org/stable/c/d35acc1be3480505b5931f17e4ea9b7617fea4d3
    Patch
  • git.kernel.org https://git.kernel.org/stable/c/e3f6745006dc9423d2b065b90f191cfa11b1b584
    Patch
  • lists.debian.org https://lists.debian.org/debian-lts-announce/2025/10/msg00007.html
    Third Party Advisory
  • lists.debian.org https://lists.debian.org/debian-lts-announce/2025/10/msg00008.html
    Third Party Advisory

Remediation

  • git.kernel.org https://git.kernel.org/stable/c/20f68e6a9e41693cb0e55e5b9ebbcb40983a4b8f
    Patch
  • git.kernel.org https://git.kernel.org/stable/c/3aaa7c01cf19d9b9bb64b88b65c3a6fd05da2eb4
    Patch
  • git.kernel.org https://git.kernel.org/stable/c/4483d8b9127591c60c4eb789d6cab953bc4522a9
    Patch
  • git.kernel.org https://git.kernel.org/stable/c/46c15c9d0f65c9ba857d63f53264f4b17e8a715f
    Patch
  • git.kernel.org https://git.kernel.org/stable/c/53d11560e957d53ee87a0653d258038ce12361b7
    Patch
  • git.kernel.org https://git.kernel.org/stable/c/93f9eeb678d4c9c1abf720b3615fa8299a490845
    Patch
  • git.kernel.org https://git.kernel.org/stable/c/d35acc1be3480505b5931f17e4ea9b7617fea4d3
    Patch
  • git.kernel.org https://git.kernel.org/stable/c/e3f6745006dc9423d2b065b90f191cfa11b1b584
    Patch