PT-2025-44277 · Linux+3 · Linux Kernel+3

Published

2025-10-29

·

Updated

2026-05-26

·

CVE-2025-40083

None

No severity ratings or metrics are available. When they are, we'll update the corresponding info on the page.
Name of the Vulnerable Software and Affected Versions Linux kernel (affected versions not specified)
Description A flaw exists in the Linux kernel’s sch qfq scheduler within the agg dequeue function (net/sched/sch qfq.c). A null dereference could occur when cl->qdisc->ops->peek(cl->qdisc) returns NULL, potentially leading to a system crash. The issue was addressed by checking the return value before use, mirroring a similar approach in sch hfsc.c. Changes were made to qdisc warn nonwc and qdisc peek len to avoid code duplication and facilitate the fix.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Related Identifiers

AZL-69027
CVE-2025-40083
DLA-4404-1
ECHO-4F4B-F4AF-6A05
OESA-2026-1303
OESA-2026-1304
OESA-2026-1339
OPENSUSE-SU-2025:20172-1
SUSE-SU-2025:4393-1
SUSE-SU-2025:4422-1
SUSE-SU-2025:4505-1
SUSE-SU-2025:4515-1
SUSE-SU-2025:4516-1
SUSE-SU-2025:4517-1
SUSE-SU-2025:4521-1
SUSE-SU-2026:20012-1
SUSE-SU-2026:20015-1
SUSE-SU-2026:20021-1
SUSE-SU-2026:20039-1
SUSE-SU-2026:20059-1
SUSE-SU-2026:20473-1
SUSE-SU-2026:20496-1
USN-8095-1
USN-8095-2
USN-8095-3
USN-8095-4
USN-8095-5
USN-8096-1
USN-8096-2
USN-8096-3
USN-8096-4
USN-8096-5
USN-8100-1
USN-8116-1
USN-8125-1
USN-8126-1
USN-8141-1
USN-8163-1
USN-8163-2
USN-8165-1
USN-8243-1
USN-8261-1

Affected Products

Debian
Linuxmint
Linux Kernel
Ubuntu