PT-2025-33708 · Linux+5 · Linux Kernel+5

Willsroot

·

Published

2025-01-01

·

Updated

2026-04-20

·

CVE-2025-38553

CVSS v3.1

5.5

Medium

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions: Linux kernel (affected versions not specified)
Description: A flaw exists in the Linux kernel's net/sched subsystem related to the handling of netem (network emulator) queuing disciplines (qdiscs). The duplication prevention logic within netem enqueue fails when a netem instance resides within a qdisc tree alongside other netem instances. This can lead to a soft lockup and an out-of-memory (OOM) loop during netem dequeue. The issue arises from the potential for duplicated netem instances to exist within the same qdisc tree. Previous attempts to address this included tracking duplication status in the sk buff structure, restricting recursion depth, and using metadata in netem skb cb, but these were deemed either too specific, bypassable, or overly complex. The current solution prevents a duplicating netem from existing in the same tree as other netems.
Recommendations: At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

DoS

Uncontrolled Recursion

Improper Locking

Weakness Enumeration

Related Identifiers

AZL-66437
AZL-73791
BDU:2025-15553
CVE-2025-38553
DLA-4327-1
DLA-4328-1
ECHO-030E-8A36-AD8F
MGASA-2025-0234
MGASA-2025-0235
OPENSUSE-SU-2025:20081-1
SUSE-SU-2025:03272-1
SUSE-SU-2025:03290-1
SUSE-SU-2025:03301-1
SUSE-SU-2025:03382-1
SUSE-SU-2025:03602-1
SUSE-SU-2025:03613-1
SUSE-SU-2025:03614-1
SUSE-SU-2025:03615-1
SUSE-SU-2025:03626-1
SUSE-SU-2025:03628-1
SUSE-SU-2025:03633-1
SUSE-SU-2025:03634-1
SUSE-SU-2025:20653-1
SUSE-SU-2025:20669-1
SUSE-SU-2025:20739-1
SUSE-SU-2025:20756-1
SUSE-SU-2025:21074-1
SUSE-SU-2025:21139-1
SUSE-SU-2025:21179-1
SUSE-SU-2025:3716-1
SUSE-SU-2025:3761-1
SUSE-SU-2025_03272-1
SUSE-SU-2025_03290-1
SUSE-SU-2025_03301-1
SUSE-SU-2025_03382-1
USN-7879-1
USN-7879-2
USN-7879-3
USN-7879-4
USN-7880-1
USN-7909-1
USN-7909-2
USN-7909-3
USN-7909-4
USN-7909-5
USN-7910-1
USN-7910-2
USN-7933-1
USN-7934-1
USN-7938-1
USN-8028-1
USN-8028-2
USN-8028-3
USN-8028-4
USN-8028-5
USN-8028-6
USN-8028-7
USN-8028-8
USN-8031-1
USN-8031-2
USN-8031-3
USN-8052-1
USN-8052-2
USN-8074-1
USN-8074-2
USN-8126-1

Affected Products

Debian
Linuxmint
Linux Kernel
Red Os
Suse
Ubuntu