CVE-2025-37953
In the Linux kernel, the following vulnerability has been resolved:
sch_htb: make htb_deactivate() idempotent
Alan reported a NULL pointer dereference in htb_next_rb_node() after we made htb_qlen_notify() idempotent.
It turns out in the following case it introduced some regression:
For htb_next_rb_node(), after calling the 1st htb_deactivate(), the clprio[prio]->ptr could be already set to NULL, which means htb_next_rb_node() is vulnerable here.
For htb_deactivate(), although we checked qlen before calling it, in case of qlen==0 after qdisc_tree_reduce_backlog(), we may call it again which triggers the warning inside.
Leer descripción completaMostrar menos
To fix the issues here, we need to:
1) Make htb_deactivate() idempotent, that is, simply return if we already call it before. 2) Make htb_next_rb_node() safe against ptr==NULL.
Many thanks to Alan for testing and for the reproducer.
Detalles técnicos trazas, registros y código del informe original
htb_dequeue_tree():
|-> fq_codel_dequeue()
|-> qdisc_tree_reduce_backlog()
|-> htb_qlen_notify()
|-> htb_deactivate()
|-> htb_next_rb_node()
|-> htb_deactivate()CVSS
- Versión: 3.1
- Vector: CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
- Puntuación base: 5.5
Probabilidad de explotación (EPSS)
- Probabilidad de explotación en los próximos 30 días: 0.19%
- Percentil entre todas las CVEs puntuadas: 7
- Fecha de la puntuación: 6/10/2026
EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).
Tecnologías afectadas (2)
CWE
- CWE-476
Referencias
- https://git.kernel.org/stable/c/31ff70ad39485698cf779f2078132d80b57f6c07
- https://git.kernel.org/stable/c/3769478610135e82b262640252d90f6efb05be71
- https://git.kernel.org/stable/c/98cd7ed92753090a714f0802d4434314526fe61d
- https://git.kernel.org/stable/c/99ff8a20fd61315bf9ae627440a5ff07d22ee153
- https://git.kernel.org/stable/c/a9945f7cf1709adc5d2d31cb6cfc85627ce299a8
- https://git.kernel.org/stable/c/c2d25fddd867ce20a266806634eeeb5c30cb520c
- https://git.kernel.org/stable/c/c4792b9e38d2f61b07eac72f10909fa76130314b
- https://git.kernel.org/stable/c/c928dd4f6bf0c25c72b11824a1e9ac9bd37296a0
- https://lists.debian.org/debian-lts-announce/2025/08/msg00010.html
JSON original (NVD)
Mostrar
{
"id": "CVE-2025-37953",
"cveTags": [],
"metrics": {
"cvssMetricV31": [
{
"type": "Primary",
"source": "nvd@nist.gov",
"cvssData": {
"scope": "UNCHANGED",
"version": "3.1",
"baseScore": 5.5,
"attackVector": "LOCAL",
"baseSeverity": "MEDIUM",
"vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H",
"integrityImpact": "NONE",
"userInteraction": "NONE",
"attackComplexity": "LOW",
"availabilityImpact": "HIGH",
"privilegesRequired": "LOW",
"confidentialityImpact": "NONE"
},
"impactScore": 3.6,
"exploitabilityScore": 1.8
}
]
},
"affected": [
{
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"affectedData": [
{
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"product": "Linux",
"versions": [
{
"status": "affected",
"version": "e6b45f4de763b00dc1c55e685e2dd1aaf525d3c1",
"lessThan": "99ff8a20fd61315bf9ae627440a5ff07d22ee153",
"versionType": "git"
},
{
"status": "affected",
"version": "32ae12ce6a9f6bace186ca7335220ff59b6cc3cd",
"lessThan": "a9945f7cf1709adc5d2d31cb6cfc85627ce299a8",
"versionType": "git"
},
{
"status": "affected",
"version": "967955c9e57f8eebfccc298037d4aaf3d42bc1c9",
"lessThan": "c2d25fddd867ce20a266806634eeeb5c30cb520c",
"versionType": "git"
},
{
"status": "affected",
"version": "73cf6af13153d62f9b76eff422eea79dbc70f15e",
"lessThan": "c928dd4f6bf0c25c72b11824a1e9ac9bd37296a0",
"versionType": "git"
},
{
"status": "affected",
"version": "bbbf5e0f87078b715e7a665d662a2c0e77f044ae",
"lessThan": "31ff70ad39485698cf779f2078132d80b57f6c07",
"versionType": "git"
},
{
"status": "affected",
"version": "0a188c0e197383683fd093ab1ea6ce9a5869a6ea",
"lessThan": "98cd7ed92753090a714f0802d4434314526fe61d",
"versionType": "git"
},
{
"status": "affected",
"version": "a61f1b5921761fbaf166231418bc1db301e5bf59",
"lessThan": "c4792b9e38d2f61b07eac72f10909fa76130314b",
"versionType": "git"
},
{
"status": "affected",
"version": "5ba8b837b522d7051ef81bacf3d95383ff8edce5",
"lessThan": "3769478610135e82b262640252d90f6efb05be71",
"versionType": "git"
}
],
"programFiles": [
"net/sched/sch_htb.c"
],
"defaultStatus": "unaffected"
},
{
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"product": "Linux",
"versions": [
{
"status": "affected",
"version": "6.1.138",
"lessThan": "6.1.139",
"versionType": "semver"
},
{
"status": "affected",
"version": "6.6.90",
"lessThan": "6.6.91",
"versionType": "semver"
},
{
"status": "affected",
"version": "6.12.28",
"lessThan": "6.12.29",
"versionType": "semver"
},
{
"status": "affected",
"version": "6.14.6",
"lessThan": "6.14.7",
"versionType": "semver"
}
],
"programFiles": [
"net/sched/sch_htb.c"
],
"defaultStatus": "unaffected"
}
]
}
],
"published": "2025-05-20T16:15:33.483",
"references": [
{
"url": "https://git.kernel.org/stable/c/31ff70ad39485698cf779f2078132d80b57f6c07",
"tags": [
"Patch"
],
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
},
{
"url": "https://git.kernel.org/stable/c/3769478610135e82b262640252d90f6efb05be71",
"tags": [
"Patch"
],
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
},
{
"url": "https://git.kernel.org/stable/c/98cd7ed92753090a714f0802d4434314526fe61d",
"tags": [
"Patch"
],
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
},
{
"url": "https://git.kernel.org/stable/c/99ff8a20fd61315bf9ae627440a5ff07d22ee153",
"tags": [
"Patch"
],
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
},
{
"url": "https://git.kernel.org/stable/c/a9945f7cf1709adc5d2d31cb6cfc85627ce299a8",
"tags": [
"Patch"
],
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
},
{
"url": "https://git.kernel.org/stable/c/c2d25fddd867ce20a266806634eeeb5c30cb520c",
"tags": [
"Patch"
],
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
},
{
"url": "https://git.kernel.org/stable/c/c4792b9e38d2f61b07eac72f10909fa76130314b",
"tags": [
"Patch"
],
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
},
{
"url": "https://git.kernel.org/stable/c/c928dd4f6bf0c25c72b11824a1e9ac9bd37296a0",
"tags": [
"Patch"
],
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
},
{
"url": "https://lists.debian.org/debian-lts-announce/2025/08/msg00010.html",
"tags": [
"Third Party Advisory"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
}
],
"vulnStatus": "Analyzed",
"weaknesses": [
{
"type": "Primary",
"source": "nvd@nist.gov",
"description": [
{
"lang": "en",
"value": "CWE-476"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\nsch_htb: make htb_deactivate() idempotent\n\nAlan reported a NULL pointer dereference in htb_next_rb_node()\nafter we made htb_qlen_notify() idempotent.\n\nIt turns out in the following case it introduced some regression:\n\nhtb_dequeue_tree():\n |-> fq_codel_dequeue()\n |-> qdisc_tree_reduce_backlog()\n |-> htb_qlen_notify()\n |-> htb_deactivate()\n |-> htb_next_rb_node()\n |-> htb_deactivate()\n\nFor htb_next_rb_node(), after calling the 1st htb_deactivate(), the\nclprio[prio]->ptr could be already set to NULL, which means\nhtb_next_rb_node() is vulnerable here.\n\nFor htb_deactivate(), although we checked qlen before calling it, in\ncase of qlen==0 after qdisc_tree_reduce_backlog(), we may call it again\nwhich triggers the warning inside.\n\nTo fix the issues here, we need to:\n\n1) Make htb_deactivate() idempotent, that is, simply return if we\n already call it before.\n2) Make htb_next_rb_node() safe against ptr==NULL.\n\nMany thanks to Alan for testing and for the reproducer."
},
{
"lang": "es",
"value": "En el kernel de Linux, se ha resuelto la siguiente vulnerabilidad: sch_htb: hacer que htb_deactivate() sea idempotente. Alan informó una desreferencia de puntero NULL en htb_next_rb_node() después de que htb_qlen_notify() fuera idempotente. Resulta que en el siguiente caso introdujo alguna regresión: htb_dequeue_tree(): |-> fq_codel_dequeue() |-> qdisc_tree_reduce_backlog() |-> htb_qlen_notify() |-> htb_deactivate() |-> htb_next_rb_node() |-> htb_deactivate() Para htb_next_rb_node(), después de llamar al primer htb_deactivate(), el clprio[prio]->ptr podría estar ya establecido en NULL, lo que significa que htb_next_rb_node() es vulnerable aquí. Para htb_deactivate(), aunque verificamos qlen antes de llamarlo, en caso de qlen==0 después de qdisc_tree_reduce_backlog(), podemos llamarlo nuevamente, lo que activa la advertencia interna. Para solucionar estos problemas, necesitamos: 1) Hacer que htb_deactivate() sea idempotente, es decir, que simplemente regrese si ya lo llamamos. 2) Hacer que htb_next_rb_node() sea seguro contra ptr==NULL. Muchas gracias a Alan por las pruebas y por el reproductor."
}
],
"lastModified": "2026-06-17T09:15:45.963",
"configurations": [
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:6.1.138:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "BC65592C-4F4A-41FF-A271-60B010E949AF"
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:6.6.90:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "D59F317C-54D9-46AF-9BE7-9679E9BD1AEF"
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:6.12.28:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "F3B49C5B-6A74-41DF-A9E0-C09A2D71CAD9"
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:6.14.6:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "33C3A487-6E91-4036-AF1B-D478270395FA"
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:6.15:rc2:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "4C9D071F-B28E-46EC-AC61-22B913390211"
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:6.15:rc3:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "13FC0DDE-E513-465E-9E81-515702D49B74"
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:6.15:rc4:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "8C7B5B0E-4EEB-48F5-B4CF-0935A7633845"
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:6.15:rc5:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "2D240580-3048-49B2-9E27-F115A9DF8224"
}
],
"operator": "OR"
}
]
},
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:o:debian:debian_linux:11.0:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "FA6FEEC2-9F11-4643-8827-749718254FED"
}
],
"operator": "OR"
}
]
}
],
"sourceIdentifier": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
}