CVE-2025-68325

NONE EPSS 7.8%
Published Dec 18, 20256mo ago · Modified Jun 17, 20261w ago
Find Similar
Published Dec 18, 2025 6mo ago
Last Modified Jun 17, 2026 1w ago

Description

In the Linux kernel, the following vulnerability has been resolved: net/sched: sch_cake: Fix incorrect qlen reduction in cake_drop In cake_drop(), qdisc_tree_reduce_backlog() is used to update the qlen and backlog of the qdisc hierarchy. Its caller, cake_enqueue(), assumes that the parent qdisc will enqueue the current packet. However, this assumption breaks when cake_enqueue() returns NET_XMIT_CN: the parent qdisc stops enqueuing current packet, leaving the tree qlen/backlog accounting inconsistent. This mismatch can lead to a NULL dereference (e.g., when the parent Qdisc is qfq_qdisc). This patch computes the qlen/backlog delta in a more robust way by observing the difference before and after the series of cake_drop() calls, and then compensates the qdisc tree accounting if cake_enqueue() returns NET_XMIT_CN. To ensure correct compensation when ACK thinning is enabled, a new variable is introduced to keep qlen unchanged.

Threat Intelligence

EPSS Exploit Probability
7.8% percentile
Exploit & Patch Status
No Known Exploit
No Patch Available

References 8

  • git.kernel.org https://git.kernel.org/stable/c/0b6216f9b3d1c33c76f74511026e5de5385ee520
  • git.kernel.org https://git.kernel.org/stable/c/38abf6e931b169ea88d7529b49096f53a5dcf8fe
  • git.kernel.org https://git.kernel.org/stable/c/3ed6c458530a547ed0c9ea0b02b19bab620be88b
  • git.kernel.org https://git.kernel.org/stable/c/529c284cc2815c8350860e9a31722050fe7117cb
  • git.kernel.org https://git.kernel.org/stable/c/9fefc78f7f02d71810776fdeb119a05a946a27cc
  • git.kernel.org https://git.kernel.org/stable/c/a3f4e3de41a3f115db35276c6b186ccbc913934a
  • git.kernel.org https://git.kernel.org/stable/c/d01f0e072dadb02fe10f436b940dd957aff0d7d4
  • git.kernel.org https://git.kernel.org/stable/c/fcb91be52eb6e92e00b533ebd7c77fecada537e1

Remediation

No remediation data recorded yet

Check vendor advisories and the NVD entry for patch availability.