cbcvebase.
CVE-2025-21703
published 2025-02-18

CVE-2025-21703: In the Linux kernel, the following vulnerability has been resolved: netem: Update sch->q.qlen before qdisc_tree_reduce_backlog() qdisc_tree_reduce_backlog()…

PriorityP336high7.8CVSS 3.1
AVLACLPRLUINSUCHIHAH
EPSS
0.29%
21.1th percentile
In the Linux kernel, the following vulnerability has been resolved: netem: Update sch->q.qlen before qdisc_tree_reduce_backlog() qdisc_tree_reduce_backlog() notifies parent qdisc only if child qdisc becomes empty, therefore we need to reduce the backlog of the child qdisc before calling it. Otherwise it would miss the opportunity to call cops->qlen_notify(), in the case of DRR, it resulted in UAF since DRR uses ->qlen_notify() to maintain its active list.

Affected

35 ranges· showing 25
VendorProductVersion rangeFixed in
debianlinux< linux 6.1.129-1 (bookworm)linux 6.1.129-1 (bookworm)
debianlinux-6.1< linux 6.1.129-1 (bookworm)linux 6.1.129-1 (bookworm)
googlechrome_chrome
linuxlinux
linuxlinux>= 10df49cfca73dfbbdb6c4150d859f7e8926ae427 < 7b79ca9a1de6a428d486ff52fb3d602321c08f557b79ca9a1de6a428d486ff52fb3d602321c08f55
linuxlinux>= 216509dda290f6db92c816dd54b83c1df9da9e76 < 7f31d74fcc556a9166b1bb20515542de7bb939d17f31d74fcc556a9166b1bb20515542de7bb939d1
linuxlinux>= 356078a5c55ec8d2061fcc009fb8599f5b0527f9 < 6312555249082d6d8cc5321ff725df05482d8b836312555249082d6d8cc5321ff725df05482d8b83
linuxlinux>= 3824c5fad18eeb7abe0c4fc966f29959552dca3e < 1f8e3f4a4b8b90ad274dfbc66fc7d55cb582f4d51f8e3f4a4b8b90ad274dfbc66fc7d55cb582f4d5
linuxlinux>= 5.10.232 < 5.10.2355.10.235
linuxlinux>= 5.15.175 < 5.15.1795.15.179
linuxlinux>= 5.4.288 < 5.4.2915.4.291
linuxlinux>= 6.1.121 < 6.1.1296.1.129
linuxlinux>= 6.12.6 < 6.12.146.12.14
linuxlinux>= 6.6.67 < 6.6.786.6.78
linuxlinux>= 83c6ab12f08dcc09d4c5ac86fdb89736b28f1d31 < e395fec75ac2dbffc99b4bce57b7f1f3c5449f2ce395fec75ac2dbffc99b4bce57b7f1f3c5449f2c
linuxlinux>= c2047b0e216c8edce227d7c42f99ac2877dad0e4 < 98a2c685293aae122f688cde11d9334dddc5d20798a2c685293aae122f688cde11d9334dddc5d207
linuxlinux>= f8d4bc455047cf3903cd6f85f49978987dbb3027 < 839ecc583fa00fab785fde1c85a326743657fd32839ecc583fa00fab785fde1c85a326743657fd32
linuxlinux>= f8d4bc455047cf3903cd6f85f49978987dbb3027 < 638ba5089324796c2ee49af10427459c2de35f71638ba5089324796c2ee49af10427459c2de35f71
linuxlinux_kernel
linuxlinux_kernel>= 0 < 5.10.234-15.10.234-1
linuxlinux_kernel>= 0 < 6.1.129-16.1.129-1
linuxlinux_kernel>= 0 < 6.12.15-16.12.15-1
linuxlinux_kernel>= 0 < 6.12.15-16.12.15-1
linuxlinux_kernel>= 0 < 5.4.0-214.2345.4.0-214.234
linuxlinux_kernel>= 0 < 5.15.0-138.1485.15.0-138.148

CVSS provenance

nvdv3.17.8HIGHCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
osv7.8HIGH
vendor_debian7.8HIGH
vendor_msrc7.8HIGH
vendor_redhat7.8HIGH
vendor_ubuntu7.8HIGH
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.