{ "dataType": "CVE_RECORD", "dataVersion": "5.2", "cveMetadata": { "cveId": "CVE-2025-37914", "assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67", "state": "PUBLISHED", "assignerShortName": "Linux", "dateReserved": "2025-04-16T04:51:23.967Z", "datePublished": "2025-05-20T15:21:45.796Z", "dateUpdated": "2026-08-05T11:58:17.560Z" }, "containers": { "cna": { "providerMetadata": { "orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67", "shortName": "Linux", "dateUpdated": "2026-08-05T11:58:17.560Z" }, "descriptions": [ { "lang": "en", "value": "In the Linux kernel, the following vulnerability has been resolved:\n\nnet_sched: ets: Fix double list add in class with netem as child qdisc\n\nAs described in Gerrard's report [1], there are use cases where a netem\nchild qdisc will make the parent qdisc's enqueue callback reentrant.\nIn the case of ets, there won't be a UAF, but the code will add the same\nclassifier to the list twice, which will cause memory corruption.\n\nIn addition to checking for qlen being zero, this patch checks whether\nthe class was already added to the active_list (cl_is_active) before\ndoing the addition to cater for the reentrant case.\n\n[1] https://lore.kernel.org/netdev/CAHcdcOm+03OD2j6R0=YHKqmy=VgJ8xEOKuP6c7mSgnp-TEJJbw@mail.gmail.com/" } ], "metrics": [ { "cvssV3_1": { "version": "3.1", "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H", "baseScore": 7.8, "baseSeverity": "HIGH" }, "scenarios": [ { "lang": "en", "value": "AV:L - Exploitation requires configuring an ETS qdisc with a duplicating netem child via tc/rtnetlink and then transmitting a packet, all of which are local operations. Per kernel scoring guidance, tc/netlink qdisc configuration is Local.\nAC:L - With `netem duplicate 100%` the reentrant enqueue and the resulting double `list_add_tail()` occur deterministically on the very first packet — no race, no timing window, and no dependence on memory layout the attacker cannot influence. The attacker fully controls the qdisc tree, the classifier, and the traffic.\nPR:L - Qdisc creation needs CAP_NET_ADMIN, but rtnetlink checks it via `netlink_net_capable()` against the netns's user_ns, so an unprivileged user obtains it with `unshare -Urn` and configures ETS+netem on a dummy/veth/lo device inside their own namespace. No real root is needed.\nUI:N - The attacker triggers the corruption entirely on their own by sending a packet through the qdisc they configured. No victim action is required.\nS:U - The corruption is confined to kernel memory within the same security authority; no hypervisor, IOMMU, or sandbox boundary is crossed.\nC:H - The double list add corrupts the `q->active` doubly-linked list, desynchronizing the active/qlen invariant and leaving classes referencing `cl->qdisc` pointers that are freed by `qdisc_put()` before being NULLed — a use-after-free read of heap contents the attacker can groom, allowing kernel pointer and adjacent-object disclosure.\nI:H - `__list_add()` on an already-linked node performs attacker-influenced `prev->next`/`next->prev` stores, and the resulting stale-active class yields writes through a dangling `cl->qdisc` during dequeue/teardown; this is a classic list-corruption write primitive leveraged for heap grooming and control-flow hijack.\nA:H - The corrupted list causes a `CONFIG_DEBUG_LIST` `__list_add_valid()` BUG/oops, and otherwise leaves the qdisc permanently wedged — `ets_qdisc_dequeue()` returns NULL with `sch->q.qlen > 0`, stalling the device's transmit path — plus NULL/dangling `cl->qdisc->ops->peek()` dereferences leading to a kernel panic." } ] } ], "affected": [ { "product": "Linux", "vendor": "Linux", "defaultStatus": "unaffected", "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git", "programFiles": [ "net/sched/sch_ets.c" ], "versions": [ { "version": "dcc68b4d8084e1ac9af0d4022d6b1aff6a139a33", "lessThan": "24388ba0a1b1b6d4af1b205927ac7f7b119ee4ea", "status": "affected", "versionType": "git" }, { "version": "dcc68b4d8084e1ac9af0d4022d6b1aff6a139a33", "lessThan": "554acc5a2ea9703e08023eb9a003f9e5a830a502", "status": "affected", "versionType": "git" }, { "version": "dcc68b4d8084e1ac9af0d4022d6b1aff6a139a33", "lessThan": "9efb6a0fa88e0910d079fdfeb4f7ce4d4ac6c990", "status": "affected", "versionType": "git" }, { "version": "dcc68b4d8084e1ac9af0d4022d6b1aff6a139a33", "lessThan": "72c3da7e6ceb74e74ddbb5a305a35c9fdfcac6e3", "status": "affected", "versionType": "git" }, { "version": "dcc68b4d8084e1ac9af0d4022d6b1aff6a139a33", "lessThan": "1f01e9f961605eb397c6ecd1d7b0233dfbf9077c", "status": "affected", "versionType": "git" }, { "version": "dcc68b4d8084e1ac9af0d4022d6b1aff6a139a33", "lessThan": "bc321f714de693aae06e3786f88df2975376d996", "status": "affected", "versionType": "git" }, { "version": "dcc68b4d8084e1ac9af0d4022d6b1aff6a139a33", "lessThan": "1a6d0c00fa07972384b0c308c72db091d49988b6", "status": "affected", "versionType": "git" } ] }, { "product": "Linux", "vendor": "Linux", "defaultStatus": "affected", "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git", "programFiles": [ "net/sched/sch_ets.c" ], "versions": [ { "version": "5.6", "status": "affected" }, { "version": "0", "lessThan": "5.6", "status": "unaffected", "versionType": "semver" }, { "version": "5.10.238", "lessThanOrEqual": "5.10.*", "status": "unaffected", "versionType": "semver" }, { "version": "5.15.182", "lessThanOrEqual": "5.15.*", "status": "unaffected", "versionType": "semver" }, { "version": "6.1.138", "lessThanOrEqual": "6.1.*", "status": "unaffected", "versionType": "semver" }, { "version": "6.6.90", "lessThanOrEqual": "6.6.*", "status": "unaffected", "versionType": "semver" }, { "version": "6.12.28", "lessThanOrEqual": "6.12.*", "status": "unaffected", "versionType": "semver" }, { "version": "6.14.6", "lessThanOrEqual": "6.14.*", "status": "unaffected", "versionType": "semver" }, { "version": "6.15", "lessThanOrEqual": "*", "status": "unaffected", "versionType": "original_commit_for_fix" } ] } ], "cpeApplicability": [ { "nodes": [ { "operator": "OR", "negate": false, "cpeMatch": [ { "vulnerable": true, "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*", "versionStartIncluding": "5.6", "versionEndExcluding": "5.10.238" }, { "vulnerable": true, "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*", "versionStartIncluding": "5.6", "versionEndExcluding": "5.15.182" }, { "vulnerable": true, "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*", "versionStartIncluding": "5.6", "versionEndExcluding": "6.1.138" }, { "vulnerable": true, "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*", "versionStartIncluding": "5.6", "versionEndExcluding": "6.6.90" }, { "vulnerable": true, "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*", "versionStartIncluding": "5.6", "versionEndExcluding": "6.12.28" }, { "vulnerable": true, "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*", "versionStartIncluding": "5.6", "versionEndExcluding": "6.14.6" }, { "vulnerable": true, "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*", "versionStartIncluding": "5.6", "versionEndExcluding": "6.15" } ] } ] } ], "references": [ { "url": "https://git.kernel.org/stable/c/24388ba0a1b1b6d4af1b205927ac7f7b119ee4ea" }, { "url": "https://git.kernel.org/stable/c/554acc5a2ea9703e08023eb9a003f9e5a830a502" }, { "url": "https://git.kernel.org/stable/c/9efb6a0fa88e0910d079fdfeb4f7ce4d4ac6c990" }, { "url": "https://git.kernel.org/stable/c/72c3da7e6ceb74e74ddbb5a305a35c9fdfcac6e3" }, { "url": "https://git.kernel.org/stable/c/1f01e9f961605eb397c6ecd1d7b0233dfbf9077c" }, { "url": "https://git.kernel.org/stable/c/bc321f714de693aae06e3786f88df2975376d996" }, { "url": "https://git.kernel.org/stable/c/1a6d0c00fa07972384b0c308c72db091d49988b6" } ], "title": "net_sched: ets: Fix double list add in class with netem as child qdisc", "x_generator": { "engine": "bippy-1.2.0" } }, "adp": [ { "title": "CVE Program Container", "references": [ { "url": "https://lists.debian.org/debian-lts-announce/2025/10/msg00007.html" }, { "url": "https://lists.debian.org/debian-lts-announce/2025/08/msg00010.html" } ], "providerMetadata": { "orgId": "af854a3a-2127-422b-91ae-364da2661108", "shortName": "CVE", "dateUpdated": "2025-11-03T19:57:16.482Z" } } ] } }