Junglewise Threat Intelligence

CVE-2025-39677: Linux Kernel integer underflow in qdisc_dequeue_internal

CVE-2025-39677 · Severity: high · CVSS 7.8 · Published 2025-09-05

Technologies: Linux Kernel. Vendors: Linux.

Executive brief

A vulnerability in the Linux kernel's networking subsystem could allow a local user to cause a system malfunction. The issue exists in how the system tracks network traffic queues, specifically when managing data limits. If exploited, this could lead to an integer underflow, potentially causing a system crash or allowing unauthorized access to system memory.

Technical details

A vulnerability in net/sched/sch_generic.h and various qdisc implementations (hhf, fq, fq_codel, fq_pie, codel, pie) occurs due to incorrect backlog accounting in qdisc_dequeue_internal. When a Token Bucket Filter (TBF) parent runs out of tokens, socket buffers (skbs) are placed in gso_skb. The qdisc_dequeue_internal function fails to decrement the backlog counter when pulling from gso_skb, leading to a mismatch between the actual queue length and the reported backlog. This inconsistency causes an integer underflow in qdisc_tree_reduce_backlog when packets are dropped to satisfy new limits, potentially resulting in a denial of service or other memory-related corruption. The fix unifies backlog adjustment logic across the affected qdiscs.

Affected products

  • Linux Linux Kernel 3.5 to 6.16.4, 6.17-rc1, 6.17-rc2

Timeline

  • 2025-08-12: other: Patch authored
  • 2025-09-05: disclosed: CVE published

References

Related threats