CVE-2025-38278

MEDIUM

Linux Kernel 6.5-6.6.93, 6.7-6.12.33, 6.13-6.15.2 - Denial of Service via TC_HTB_LEAF_DEL_LAST Callback

Title source: llm
STIX 2.1

Description

In the Linux kernel, the following vulnerability has been resolved: octeontx2-pf: QOS: Refactor TC_HTB_LEAF_DEL_LAST callback This patch addresses below issues, 1. Active traffic on the leaf node must be stopped before its send queue is reassigned to the parent. This patch resolves the issue by marking the node as 'Inner'. 2. During a system reboot, the interface receives TC_HTB_LEAF_DEL and TC_HTB_LEAF_DEL_LAST callbacks to delete its HTB queues. In the case of TC_HTB_LEAF_DEL_LAST, although the same send queue is reassigned to the parent, the current logic still attempts to update the real number of queues, leadning to below warnings New queues can't be registered after device unregistration. WARNING: CPU: 0 PID: 6475 at net/core/net-sysfs.c:1714 netdev_queue_update_kobjects+0x1e4/0x200

Scores

CVSS v3 5.5
EPSS 0.0015
EPSS Percentile 5.2%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H

Details

Status published
Products (14)
linux/Kernel 6.13.0 - 6.15.3linux
linux/Kernel 6.5.0 - 6.6.94linux
linux/Kernel 6.7.0 - 6.12.34linux
Linux/Linux < 6.5
Linux/Linux 5e6808b4c68d7882971514ab3279926eb07c8b2d - 5df8db01d6a4e9c35a5ba5d7e130d5cecd3ffcb4
Linux/Linux 5e6808b4c68d7882971514ab3279926eb07c8b2d - 67af4ec948e8ce3ea53a9cf614d01fddf172e56d
Linux/Linux 5e6808b4c68d7882971514ab3279926eb07c8b2d - ec62c99914a79d84c8de5ba1b94d62f2ed721f2a
Linux/Linux 5e6808b4c68d7882971514ab3279926eb07c8b2d - f1fca0eae5a0573f226f46c6871260278e7dda12
Linux/Linux 6.12.34 - 6.12.*
Linux/Linux 6.15.3 - 6.15.*
... and 4 more
Published Jul 10, 2025
Tracked Since Feb 18, 2026