Junglewise Threat Intelligence

CVE-2025-39766: Linux Kernel CAKE scheduler incorrect return code in cake_enqueue

CVE-2025-39766 · Severity: high · CVSS 7.8 · Published 2025-09-11

Technologies: Linux Kernel. Vendors: Linux.

Executive brief

A vulnerability in the Linux kernel's networking subsystem could allow a local user to trigger system warnings or instability. The issue occurs when the system's network traffic controller incorrectly reports that data was successfully sent even when it was dropped due to memory limits. This inconsistency can lead to internal kernel errors that may impact system availability or performance.

Technical details

A logic error exists in the 'cake_enqueue' function within 'net/sched/sch_cake.c' of the Linux kernel. When the 'buffer_limit' is exceeded, the CAKE (Common Applications Kept Enhanced) qdisc drops packets but incorrectly returns 'NET_XMIT_SUCCESS' instead of 'NET_XMIT_CN' (Congestion Notification). This causes parent schedulers like HTB (Hierarchical Token Bucket) to attempt to activate child qdiscs that are actually empty, triggering a kernel WARNING in 'htb_activate'. An attacker with local access could potentially exploit this to cause a denial-of-service or system instability by configuring specific network queueing disciplines with low memory limits. The fix ensures the correct congestion notification is returned when packets are dropped from the same flow.

Affected products

  • Linux Linux Kernel 4.19 to 5.4.297, 5.5 to 5.10.241, 5.11 to 5.15.190, 5.16 to 6.1.149, 6.2 to 6.6.103, 6.7 to 6.12.44, 6.13 to 6.16.4

Timeline

  • 2025-08-19: patched: Initial patch submitted by William Liu
  • 2025-09-11: disclosed: CVE-2025-39766 published

References

Related threats