vulnerability
Amazon Linux AMI 2: CVE-2025-21971: Security patch for kernel (Multiple Advisories)
| Severity | CVSS | Published | Added | Modified |
|---|---|---|---|---|
| 5 | (AV:L/AC:L/Au:S/C:N/I:N/A:C) | Apr 1, 2025 | Jun 23, 2025 | May 20, 2026 |
Description
In the Linux kernel, the following vulnerability has been resolved:
net_sched: Prevent creation of classes with TC_H_ROOT
The function qdisc_tree_reduce_backlog() uses TC_H_ROOT as a termination
condition when traversing up the qdisc tree to update parent backlog
counters. However, if a class is created with classid TC_H_ROOT, the
traversal terminates prematurely at this class instead of reaching the
actual root qdisc, causing parent statistics to be incorrectly maintained.
In case of DRR, this could lead to a crash as reported by Mingi Cho.
Prevent the creation of any Qdisc class with classid TC_H_ROOT
(0xFFFFFFFF) across all qdisc types, as suggested by Jamal.
Solutions
References
- AMAZON-AL2/ALAS2KERNEL-5.10-2025-090
- AMAZON-AL2/ALAS2KERNEL-5.15-2025-070
- AMAZON-AL2/ALAS2KERNEL-5.4-2025-100
- AMAZON-AL2/ALASKERNEL-5.10-2025-090
- AMAZON-AL2/ALASKERNEL-5.15-2025-070
- AMAZON-AL2/ALASKERNEL-5.4-2025-100
- CVE-2025-21971
- https://attackerkb.com/topics/CVE-2025-21971
- CWE-835
- EUVD-EUVD-2025-9349
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2025-9349
2026 Global Threat Landscape Report
The predictive window has collapsed. Exploitation follows disclosure in days. See how attackers are accelerating and how to stay ahead.