vulnerability
Ubuntu: (Multiple Advisories) (CVE-2025-21971): Linux kernel vulnerabilities
Severity | CVSS | Published | Added | Modified |
---|---|---|---|---|
5 | (AV:L/AC:L/Au:S/C:N/I:N/A:C) | Apr 1, 2025 | May 8, 2025 | Jun 3, 2025 |
Description
In the Linux kernel, the following vulnerability has been resolved:
net_sched: Prevent creation of classes with TC_H_ROOT
The function qdisc_tree_reduce_backlog() uses TC_H_ROOT as a termination
condition when traversing up the qdisc tree to update parent backlog
counters. However, if a class is created with classid TC_H_ROOT, the
traversal terminates prematurely at this class instead of reaching the
actual root qdisc, causing parent statistics to be incorrectly maintained.
In case of DRR, this could lead to a crash as reported by Mingi Cho.
Prevent the creation of any Qdisc class with classid TC_H_ROOT
(0xFFFFFFFF) across all qdisc types, as suggested by Jamal.
Solution(s)
References
- CVE-2025-21971
- https://attackerkb.com/topics/CVE-2025-21971
- UBUNTU-USN-7496-1
- UBUNTU-USN-7496-2
- UBUNTU-USN-7496-3
- UBUNTU-USN-7496-4
- UBUNTU-USN-7496-5
- UBUNTU-USN-7506-1
- UBUNTU-USN-7506-2
- UBUNTU-USN-7506-3
- UBUNTU-USN-7506-4
- UBUNTU-USN-7510-1
- UBUNTU-USN-7510-2
- UBUNTU-USN-7510-3
- UBUNTU-USN-7510-4
- UBUNTU-USN-7510-5
- UBUNTU-USN-7510-6
- UBUNTU-USN-7510-7
- UBUNTU-USN-7510-8
- UBUNTU-USN-7511-1
- UBUNTU-USN-7511-2
- UBUNTU-USN-7511-3
- UBUNTU-USN-7512-1
- UBUNTU-USN-7513-1
- UBUNTU-USN-7513-2
- UBUNTU-USN-7513-3
- UBUNTU-USN-7513-4
- UBUNTU-USN-7513-5
- UBUNTU-USN-7514-1
- UBUNTU-USN-7515-1
- UBUNTU-USN-7515-2
- UBUNTU-USN-7516-1
- UBUNTU-USN-7516-2
- UBUNTU-USN-7516-3
- UBUNTU-USN-7516-4
- UBUNTU-USN-7516-5
- UBUNTU-USN-7516-6
- UBUNTU-USN-7516-7
- UBUNTU-USN-7516-8
- UBUNTU-USN-7516-9
- UBUNTU-USN-7517-1
- UBUNTU-USN-7517-2
- UBUNTU-USN-7517-3
- UBUNTU-USN-7518-1
- UBUNTU-USN-7521-1
- UBUNTU-USN-7521-2
- UBUNTU-USN-7521-3
- UBUNTU-USN-7522-1
- UBUNTU-USN-7523-1
- UBUNTU-USN-7524-1
- UBUNTU-USN-7539-1
- UBUNTU-USN-7540-1

Explore Exposure Command
Confidently identify and prioritize exposures from endpoint to cloud with full attack surface visibility and threat-aware risk context.