net/sched: Abort __tc_modify_qdisc if parent class does not exist
Published Jul 25, 2025
5.5
MEDIUMCVSS 3.1
EPSS 0.17%
Description
Lion's patch [1] revealed an ancient bug in the qdisc API. Whenever a user creates/modifies a qdisc specifying as a parent another qdisc, the qdisc API will, during grafting, detect that the user is not trying to attach to a class and reject. However grafting is performed after qdisc_create (and thus the qdiscs' init callback) is executed. In qdiscs that eventually call qdisc_tree_reduce_backlog during init or change (such as fq, hhf, choke, etc), an issue arises. For example, executing the following commands:
sudo tc qdisc add dev lo root handle a: htb default 2 sudo tc qdisc add dev lo parent a: handle beef fq
Qdiscs such as fq, hhf, choke, etc unconditionally invoke qdisc_tree_reduce_backlog() in their control path init() or change() which then causes a failure to find the child class; however, that does not stop the unconditional invocation of the assumed child qdisc's qlen_notify with a null class. All these qdiscs make the assumption that class is non-null.
The solution is ensure that qdisc_leaf() which looks up the parent class, and is invoked prior to qdisc_create(), should return failure on not finding the class. In this patch, we leverage qdisc_leaf to return ERR_PTRs whenever the parentid doesn't correspond to a class, so that we can detect it earlier on and abort before qdisc_create is called.
[1] https://lore.kernel.org/netdev/d912cbd7-193b-4269-9857-525bee8bbb6a@gmail.com/
Affected products
-
- Version StatusaffectedConstraints
- Version StatusaffectedConstraints
- Version StatusaffectedConstraints
- Version StatusaffectedConstraints
- Version StatusaffectedConstraints
- Version StatusaffectedConstraints
- Version StatusaffectedConstraints
- Version StatusaffectedConstraints
- Version
-
- Version 2.6.20StatusaffectedConstraints-
- Version 0StatusunaffectedConstraints<2.6.20
- Version 5.10.240StatusunaffectedConstraints<=5.10.*
- Version 5.15.189StatusunaffectedConstraints<=5.15.*
- Version 5.4.296StatusunaffectedConstraints<=5.4.*
- Version 6.1.146StatusunaffectedConstraints<=6.1.*
- Version 6.12.39StatusunaffectedConstraints<=6.12.*
- Version 6.15.7StatusunaffectedConstraints<=6.15.*
- Version 6.16StatusunaffectedConstraints<=*
- Version 6.6.99StatusunaffectedConstraints<=6.6.*
- Version
Default status is the baseline for the product, each version can override it (e.g. patched versions marked unaffected).
| Vendor | Product | Default status | Versions | |||||||||||||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| Linux | Linux | unaffected |
| |||||||||||||||||||||||||||||||||
| Linux | Linux | affected |
|
Configuration 1
- ≥ 2.6.20 · < 5.4.296
- ≥ 5.5 · < 5.10.240
- ≥ 5.11 · < 5.15.189
- ≥ 5.16 · < 6.1.146
- ≥ 6.2 · < 6.6.99
- ≥ 6.7 · < 6.12.39
- ≥ 6.13 · < 6.15.7
- 6.16
- 6.16
- 6.16
- 6.16
- 6.16
Configuration 2
- 11.0
No data.
Red Hat Enterprise Linux 10
kernel
Fix deferred
Red Hat Enterprise Linux 6
kernel
Out of support scope
Red Hat Enterprise Linux 7
kernel
Fix deferred
Red Hat Enterprise Linux 7
kernel-rt
Fix deferred
Red Hat Enterprise Linux 8
kernel
Fix deferred
Red Hat Enterprise Linux 8
kernel-rt
Fix deferred
Red Hat Enterprise Linux 9
kernel
Fix deferred
Red Hat Enterprise Linux 9
kernel-rt
Fix deferred
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat Enterprise Linux 10 | kernel | Fix deferred | n/a |
| Red Hat Enterprise Linux 6 | kernel | Out of support scope | n/a |
| Red Hat Enterprise Linux 7 | kernel | Fix deferred | n/a |
| Red Hat Enterprise Linux 7 | kernel-rt | Fix deferred | n/a |
| Red Hat Enterprise Linux 8 | kernel | Fix deferred | n/a |
| Red Hat Enterprise Linux 8 | kernel-rt | Fix deferred | n/a |
| Red Hat Enterprise Linux 9 | kernel | Fix deferred | n/a |
| Red Hat Enterprise Linux 9 | kernel-rt | Fix deferred | n/a |
No package ranges for this CVE.
Remediation
No remediation recorded yet.
Metrics
No CVSS v4.0 score for this CVE.
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
No CVSS v3.0 score for this CVE.
No CVSS v2.0 score for this CVE.
This CVE is not in the KEV list.
No CISA SSVC assessment for this CVE yet.
Estimated probability of exploitation in the wild in the next 30 days (FIRST EPSS). As of Oct 1, 2026.
Score over time
2025–2026- EPSS v4
- EPSS v5
Percentile over time
- EPSS v4
- EPSS v5
Table of values (3 key points)
Flat stretches are collapsed; showing up to 120 newest points.
| Date | Score | Percentile | Model |
|---|---|---|---|
| Oct 1, 2026 | 0.17% (0.00171) | 5.84th | v5 (v2026.06.15) |
| Jun 15, 2026 | 0.15% (0.00155) | 4.96th | v5 (v2026.06.15) |
| Jul 26, 2025 | 0.02% (0.00024) | 4.96th | v4 (v2025.03.14) |
References (16)
- https://access.redhat.com/security/cve/CVE-2025-38457 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=2383501 Issue Tracking
- https://cert-portal.siemens.com/productcert/html/ssa-082556.html
- https://git.kernel.org/stable/c/23c165dde88eac405eebb59051ea1fe139a45803 Patch
- https://git.kernel.org/stable/c/25452638f133ac19d75af3f928327d8016952c8e Patch
- https://git.kernel.org/stable/c/4c691d1b6b6dbd73f30ed9ee7da05f037b0c49af Patch
- https://git.kernel.org/stable/c/8ecd651ef24ab50123692a4e3e25db93cb11602a Patch
- https://git.kernel.org/stable/c/90436e72c9622c2f70389070088325a3232d339f Patch
- https://git.kernel.org/stable/c/923a276c74e25073ae391e930792ac86a9f77f1e Patch
- https://git.kernel.org/stable/c/e28a383d6485c3bb51dc5953552f76c4dea33eea Patch
- https://git.kernel.org/stable/c/ffdde7bf5a439aaa1955ebd581f5c64ab1533963 Patch
- https://lists.debian.org/debian-lts-announce/2025/10/msg00007.html Third Party Advisory
- https://lists.debian.org/debian-lts-announce/2025/10/msg00008.html Third Party Advisory
- https://lore.kernel.org/linux-cve-announce/2025072506-CVE-2025-38457-d302@gregkh/T
- https://nvd.nist.gov/vuln/detail/CVE-2025-38457
- https://www.cve.org/CVERecord?id=CVE-2025-38457
Change history (0)
No recorded changes yet.