Junglewise Threat Intelligence

CVE-2025-38468: Linux Kernel NULL pointer dereference in HTB network scheduler

CVE-2025-38468 · Severity: medium · CVSS 5.5 · Published 2025-07-28

Technologies: Linux Kernel. Vendors: Linux.

Executive brief

A vulnerability in the Linux kernel's networking subsystem could allow a local user to crash the system. The issue occurs when specific network traffic control configurations (HTB) encounter an unexpected empty data structure during packet processing. This results in a kernel panic, leading to a complete denial of service for the affected machine.

Technical details

A vulnerability exists in net/sched/sch_htb.c within the Linux kernel's Hierarchical Token Bucket (HTB) queuing discipline. The function htb_lookup_leaf contains a BUG_ON macro that triggers when it encounters an empty red-black tree (rbtree). This state can be reached when a nested qdisc (such as netem with a blackhole child) drops a packet and triggers a backlog reduction that deactivates the HTB class, clearing the rbtree before htb_lookup_leaf is called again in the same dequeue cycle. An attacker with local privileges to configure network interfaces or trigger specific packet flows can cause a kernel panic (Denial of Service). The fix replaces the BUG_ON with a NULL return check to gracefully handle the empty tree.

Affected products

  • Linux Linux Kernel 2.6.29 to 5.4.297, 5.5 to 5.10.241, 5.11 to 5.15.190, 5.16 to 6.1.147, 6.2 to 6.6.100, 6.7 to 6.12.40, 6.13 to 6.15.8

Timeline

  • 2025-07-17: patched: Initial patch submitted to Linux kernel main line.
  • 2025-07-28: advisory: CVE-2025-38468 published.

References

Related threats