PT-2025-22176 · Linux+10 · Linux Kernel+10

Published

2025-04-28

·

Updated

2026-04-20

·

CVE-2025-37914

CVSS v3.1

7.8

High

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Linux kernel (affected versions not specified)
Description A vulnerability in the Linux kernel has been resolved, related to the net sched: ets, where a netem child qdisc can cause the parent qdisc's enqueue callback to be reentrant. This can lead to memory corruption due to adding the same classifier to the list twice. The issue is fixed by checking if the class was already added to the active list before doing the addition, in addition to checking for qlen being zero.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Double Free

Weakness Enumeration

Related Identifiers

ALSA-2025:13960
ALSA-2025:13961
ALSA-2025:14420
ALSA-2025:14510
BDU:2025-11857
CESA-2025_13960
CESA-2025_13961
CVE-2025-37914
DLA-4271-1
DLA-4327-1
DSA-5925-1
ECHO-643D-A6B8-50F8
INFSA-2025_13960
INFSA-2025_13961
INFSA-2025_14420
MGASA-2025-0182
MGASA-2025-0183
OESA-2025-2532
OESA-2025-2536
OESA-2025-2537
RHSA-2025:13960
RHSA-2025:13961
RHSA-2025:14420
RHSA-2025:14510
RHSA-2025_13960
RHSA-2025_13961
RHSA-2025_14420
SUSE-SU-2025:01964-1
SUSE-SU-2025:01965-1
SUSE-SU-2025:02000-1
SUSE-SU-2025:02254-1
SUSE-SU-2025:02307-1
SUSE-SU-2025:02333-1
SUSE-SU-2025:02923-1
SUSE-SU-2025:20408-1
SUSE-SU-2025:20413-1
SUSE-SU-2025:20419-1
SUSE-SU-2025:20421-1
SUSE-SU-2025_01964-1
SUSE-SU-2025_01965-1
SUSE-SU-2025_02000-1
SUSE-SU-2025_02254-1
SUSE-SU-2025_02307-1
SUSE-SU-2025_02333-1
USN-7649-1
USN-7649-2
USN-7650-1
USN-7654-1
USN-7654-2
USN-7654-3
USN-7654-4
USN-7654-5
USN-7655-1
USN-7665-1
USN-7665-2
USN-7686-1
USN-7711-1
USN-7712-1
USN-7712-2
USN-7721-1
USN-8028-1
USN-8028-2
USN-8028-3
USN-8028-4
USN-8028-5
USN-8028-6
USN-8028-7
USN-8028-8
USN-8031-1
USN-8031-2
USN-8031-3
USN-8052-1
USN-8052-2
USN-8074-1
USN-8074-2
USN-8126-1

Affected Products

Almalinux
Astra Linux
Centos
Debian
Linuxmint
Linux Kernel
Red Hat
Red Os
Rocky Linux
Suse
Ubuntu