CNNVD-202508-2075 Information

CNNVD ID

CNNVD-202508-2075

CVE-2025-38553

  • CNNVD Published: 2025-08-19

Description (Chinese)

Linux kernel是美国Linux基金会的开源操作系统Linux所使用的内核。 Linux kernel存在安全漏洞,该漏洞源于netem_enqueue的重复预防逻辑在qdisc树中存在多个netem时失效,可能导致软锁定和OOM循环。

Description (English)

Linux Kernel is the kernel used by Linux, the Open Source Operator System of the Linux Foundation of the United States. There is a security loophole in Linux Kernel, which stems from the repeated prevention logic of netem enquee that lapses when there are multiple netems in the qdisc tree, which may lead to soft locking and OOM circulation.

Hazard Level

High

Vulnerability Type

其他

Affected Vendor

Linux

Published

2025-08-19

Last Modified

2026-02-24

References

https://git.kernel.org/stable/c/ec8e0e3d7adef940cdf9475e2352c0680189d14e https://git.kernel.org/stable/c/103c4e27ec9f5fe53022e46e976abf52c7221baf https://git.kernel.org/stable/c/250f8796006c0f2bc638ce545f601d49ae8d528b https://git.kernel.org/stable/c/795cb393e38977aa991e70a9363da0ee734b2114 https://git.kernel.org/stable/c/09317dfb681ac5a96fc69bea0c54441cf91b8270 https://git.kernel.org/stable/c/f088b6ebe8797a3f948d2cae47f34bfb45cc6522 https://git.kernel.org/stable/c/cab2809944989889f88a1a8b5cff1c78460c72cb https://git.kernel.org/stable/c/ad340a4b4adb855b18b3666f26ad65c8968e2deb https://git.kernel.org/stable/c/325f5ec67cc0a77f2d0d453445b9857f1cd06c76 https://nvd.nist.gov/vuln/detail/CVE-2025-38553 https://vigilance.fr/vulnerability/Linux-kernel-denial-of-service-via-Qdisc-Tree-Duplicating-Netems-48027

Patch

https://www.kernel.org/

Share on: