Junglewise Threat Intelligence

CVE-2025-38684: Linux Kernel NULL pointer dereference in ETS scheduler

CVE-2025-38684 · Severity: medium · CVSS 5.5 · Published 2025-09-04

Technologies: Linux Kernel. Vendors: Linux.

Executive brief

A vulnerability in the Linux kernel's networking subsystem could allow a local user to crash the system. The issue occurs within the Enhanced Transmission Selection (ETS) scheduler, which manages how network traffic is prioritized. By triggering specific changes to network queue configurations, an attacker can cause a system-wide crash (kernel panic), leading to a denial of service.

Technical details

A NULL pointer dereference exists in net/sched/sch_ets.c within the ets_qdisc_change() function. The vulnerability is caused by an inconsistent state where the 'nbands' value is updated to a new value before unused DWRR (Deficit Weighted Round Robin) queues are purged. Because functions like ets_class_find() and ets_class_is_strict() rely on the original band configuration during the cleanup process, the premature update leads to invalid memory access. A local attacker with permissions to modify network disciplines (typically requiring CAP_NET_ADMIN) can exploit this to trigger a kernel oops and system crash. The fix involves reordering operations to purge idle queues before assigning the new 'nbands' and 'nstrict' values.

Affected products

  • Linux Linux Kernel 5.11 to 5.15.190, 6.2 to 6.6.103, 6.7 to 6.12.43, 6.13 to 6.15.11

Timeline

  • 2025-08-12: patched: Initial patch authored by Davide Caratti
  • 2025-09-04: advisory: NVD publication date

References

Related threats