Executive brief
A vulnerability in the Linux kernel's networking subsystem could allow a local user to crash the system. The issue occurs when specific network traffic control configurations (HTB) encounter an unexpected empty data structure during packet processing. This results in a kernel panic, leading to a complete denial of service for the affected machine.
Technical details
A vulnerability exists in net/sched/sch_htb.c within the Linux kernel's Hierarchical Token Bucket (HTB) queuing discipline. The function htb_lookup_leaf contains a BUG_ON macro that triggers when it encounters an empty red-black tree (rbtree). This state can be reached when a nested qdisc (such as netem with a blackhole child) drops a packet and triggers a backlog reduction that deactivates the HTB class, clearing the rbtree before htb_lookup_leaf is called again in the same dequeue cycle. An attacker with local privileges to configure network interfaces or trigger specific packet flows can cause a kernel panic (Denial of Service). The fix replaces the BUG_ON with a NULL return check to gracefully handle the empty tree.
Affected products
- Linux Linux Kernel 2.6.29 to 5.4.297, 5.5 to 5.10.241, 5.11 to 5.15.190, 5.16 to 6.1.147, 6.2 to 6.6.100, 6.7 to 6.12.40, 6.13 to 6.15.8
Timeline
- 2025-07-17: patched: Initial patch submitted to Linux kernel main line.
- 2025-07-28: advisory: CVE-2025-38468 published.
References
- https://git.kernel.org/stable/c/0e1d5d9b5c5966e2e42e298670808590db5ed628
- https://git.kernel.org/stable/c/3691f84269a23f7edd263e9b6edbc27b7ae332f4
- https://git.kernel.org/stable/c/5c0506cd1b1a3b145bda2612bbf7fe78d186c355
- https://git.kernel.org/stable/c/7ff2d83ecf2619060f30ecf9fad4f2a700fca344
- https://git.kernel.org/stable/c/850226aef8d28a00cf966ef26d2f8f2bff344535
- https://git.kernel.org/stable/c/890a5d423ef0a7bd13447ceaffad21189f557301
- https://git.kernel.org/stable/c/e5c480dc62a3025b8428d4818e722da30ad6804f