7.8
HIGH CVSS 3.1
CVE-2025-37797
net_sched: hfsc: Fix a UAF vulnerability in class handling
Description

In the Linux kernel, the following vulnerability has been resolved: net_sched: hfsc: Fix a UAF vulnerability in class handling This patch fixes a Use-After-Free vulnerability in the HFSC qdisc class handling. The issue occurs due to a time-of-check/time-of-use condition in hfsc_change_class() when working with certain child qdiscs like netem or codel. The vulnerability works as follows: 1. hfsc_change_class() checks if a class has packets (q.qlen != 0) 2. It then calls qdisc_peek_len(), which for certain qdiscs (e.g., codel, netem) might drop packets and empty the queue 3. The code continues assuming the queue is still non-empty, adding the class to vttree 4. This breaks HFSC scheduler assumptions that only non-empty classes are in vttree 5. Later, when the class is destroyed, this can lead to a Use-After-Free The fix adds a second queue length check after qdisc_peek_len() to verify the queue wasn't emptied.

INFO

Published Date :

May 2, 2025, 3:15 p.m.

Last Modified :

Nov. 6, 2025, 8:48 p.m.

Remotely Exploit :

No

Source :

416baaa9-dc9f-4396-8d5f-8c081fb06d67
Affected Products

The following products are affected by CVE-2025-37797 vulnerability. Even if cvefeed.io is aware of the exact versions of the products that are affected, the information is not represented in the table below.

ID Vendor Product Action
1 Linux linux_kernel
1 Debian debian_linux
CVSS Scores
The Common Vulnerability Scoring System is a standardized framework for assessing the severity of vulnerabilities in software and systems. We collect and displays CVSS scores from various sources for each CVE.
Score Version Severity Vector Exploitability Score Impact Score Source
CVSS 3.1 HIGH [email protected]
Solution
Update the Linux kernel to a patched version to fix a Use-After-Free vulnerability.
  • Update the Linux kernel to a version that includes the fix.
  • Apply the provided patch to the Linux kernel source code.
  • Recompile and reinstall the kernel.
  • Reboot the system to load the updated kernel.
CWE - Common Weakness Enumeration

While CVE identifies specific instances of vulnerabilities, CWE categorizes the common flaws or weaknesses that can lead to vulnerabilities. CVE-2025-37797 is associated with the following CWEs:

Common Attack Pattern Enumeration and Classification (CAPEC)

Common Attack Pattern Enumeration and Classification (CAPEC) stores attack patterns, which are descriptions of the common attributes and approaches employed by adversaries to exploit the CVE-2025-37797 weaknesses.

We scan GitHub repositories to detect new proof-of-concept exploits. Following list is a collection of public exploits and proof-of-concepts, which have been published on GitHub (sorted by the most recently updated).

Results are limited to the first 15 repositories due to potential performance issues.

The following list is the news that have been mention CVE-2025-37797 vulnerability anywhere in the article.

The following table lists the changes that have been made to the CVE-2025-37797 vulnerability over time.

Vulnerability history details can be useful for understanding the evolution of a vulnerability, and for identifying the most recent changes that may impact the vulnerability's severity, exploitability, or other characteristics.

  • Initial Analysis by [email protected]

    Nov. 06, 2025

    Action Type Old Value New Value
    Added CVSS V3.1 AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
    Added CWE CWE-416
    Added CPE Configuration OR *cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* versions from (including) 6.13 up to (excluding) 6.14.5 *cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* versions from (including) 6.7 up to (excluding) 6.12.26 *cpe:2.3:o:linux:linux_kernel:6.15:rc1:*:*:*:*:*:* *cpe:2.3:o:linux:linux_kernel:6.15:rc2:*:*:*:*:*:* *cpe:2.3:o:linux:linux_kernel:6.15:rc3:*:*:*:*:*:* *cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* versions from (including) 6.2 up to (excluding) 6.6.89 *cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* versions from (including) 4.14.1 up to (excluding) 5.4.293 *cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* versions from (including) 5.5 up to (excluding) 5.10.237 *cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* versions from (including) 5.11 up to (excluding) 5.15.181 *cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* versions from (including) 5.16 up to (excluding) 6.1.136 *cpe:2.3:o:linux:linux_kernel:4.14:rc2:*:*:*:*:*:* *cpe:2.3:o:linux:linux_kernel:4.14:rc3:*:*:*:*:*:* *cpe:2.3:o:linux:linux_kernel:4.14:rc4:*:*:*:*:*:* *cpe:2.3:o:linux:linux_kernel:4.14:rc5:*:*:*:*:*:* *cpe:2.3:o:linux:linux_kernel:4.14:rc6:*:*:*:*:*:* *cpe:2.3:o:linux:linux_kernel:4.14:rc7:*:*:*:*:*:* *cpe:2.3:o:linux:linux_kernel:4.14:rc8:*:*:*:*:*:* *cpe:2.3:o:linux:linux_kernel:4.14:-:*:*:*:*:*:*
    Added CPE Configuration OR *cpe:2.3:o:debian:debian_linux:11.0:*:*:*:*:*:*:*
    Added Reference Type kernel.org: https://git.kernel.org/stable/c/20d584a33e480ae80d105f43e0e7b56784da41b9 Types: Patch
    Added Reference Type kernel.org: https://git.kernel.org/stable/c/28b09a067831f7317c3841812276022d6c940677 Types: Patch
    Added Reference Type kernel.org: https://git.kernel.org/stable/c/39b9095dd3b55d9b2743df038c32138efa34a9de Types: Patch
    Added Reference Type kernel.org: https://git.kernel.org/stable/c/3aa852e3605000d5c47035c3fc3a986d14ccfa9f Types: Patch
    Added Reference Type kernel.org: https://git.kernel.org/stable/c/3df275ef0a6ae181e8428a6589ef5d5231e58b5c Types: Patch
    Added Reference Type kernel.org: https://git.kernel.org/stable/c/86cd4641c713455a4f1c8e54c370c598c2b1cee0 Types: Patch
    Added Reference Type kernel.org: https://git.kernel.org/stable/c/bb583c88d23b72d8d16453d24856c99bd93dadf5 Types: Patch
    Added Reference Type kernel.org: https://git.kernel.org/stable/c/fcc8ede663569c704fb00a702973bd6c00373283 Types: Patch
    Added Reference Type CVE: https://lists.debian.org/debian-lts-announce/2025/05/msg00030.html Types: Mailing List, Third Party Advisory
    Added Reference Type CVE: https://lists.debian.org/debian-lts-announce/2025/05/msg00045.html Types: Mailing List, Third Party Advisory
  • CVE Modified by af854a3a-2127-422b-91ae-364da2661108

    Nov. 03, 2025

    Action Type Old Value New Value
    Added Reference https://lists.debian.org/debian-lts-announce/2025/05/msg00030.html
    Added Reference https://lists.debian.org/debian-lts-announce/2025/05/msg00045.html
  • New CVE Received by 416baaa9-dc9f-4396-8d5f-8c081fb06d67

    May. 02, 2025

    Action Type Old Value New Value
    Added Description In the Linux kernel, the following vulnerability has been resolved: net_sched: hfsc: Fix a UAF vulnerability in class handling This patch fixes a Use-After-Free vulnerability in the HFSC qdisc class handling. The issue occurs due to a time-of-check/time-of-use condition in hfsc_change_class() when working with certain child qdiscs like netem or codel. The vulnerability works as follows: 1. hfsc_change_class() checks if a class has packets (q.qlen != 0) 2. It then calls qdisc_peek_len(), which for certain qdiscs (e.g., codel, netem) might drop packets and empty the queue 3. The code continues assuming the queue is still non-empty, adding the class to vttree 4. This breaks HFSC scheduler assumptions that only non-empty classes are in vttree 5. Later, when the class is destroyed, this can lead to a Use-After-Free The fix adds a second queue length check after qdisc_peek_len() to verify the queue wasn't emptied.
    Added Reference https://git.kernel.org/stable/c/20d584a33e480ae80d105f43e0e7b56784da41b9
    Added Reference https://git.kernel.org/stable/c/28b09a067831f7317c3841812276022d6c940677
    Added Reference https://git.kernel.org/stable/c/39b9095dd3b55d9b2743df038c32138efa34a9de
    Added Reference https://git.kernel.org/stable/c/3aa852e3605000d5c47035c3fc3a986d14ccfa9f
    Added Reference https://git.kernel.org/stable/c/3df275ef0a6ae181e8428a6589ef5d5231e58b5c
    Added Reference https://git.kernel.org/stable/c/86cd4641c713455a4f1c8e54c370c598c2b1cee0
    Added Reference https://git.kernel.org/stable/c/bb583c88d23b72d8d16453d24856c99bd93dadf5
    Added Reference https://git.kernel.org/stable/c/fcc8ede663569c704fb00a702973bd6c00373283
EPSS is a daily estimate of the probability of exploitation activity being observed over the next 30 days. Following chart shows the EPSS score history of the vulnerability.
Vulnerability Scoring Details
Base CVSS Score: 7.8
Attack Vector
Attack Complexity
Privileges Required
User Interaction
Scope
Confidentiality Impact
Integrity Impact
Availability Impact