cbcvebase.
CVE-2025-21971
published 2025-04-01

CVE-2025-21971: In the Linux kernel, the following vulnerability has been resolved: net_sched: Prevent creation of classes with TC_H_ROOT The function…

PriorityP420medium5.5CVSS 3.1
AVLACLPRLUINSUCNINAH
EPSS
0.21%
11.4th percentile
In the Linux kernel, the following vulnerability has been resolved: net_sched: Prevent creation of classes with TC_H_ROOT The function qdisc_tree_reduce_backlog() uses TC_H_ROOT as a termination condition when traversing up the qdisc tree to update parent backlog counters. However, if a class is created with classid TC_H_ROOT, the traversal terminates prematurely at this class instead of reaching the actual root qdisc, causing parent statistics to be incorrectly maintained. In case of DRR, this could lead to a crash as reported by Mingi Cho. Prevent the creation of any Qdisc class with classid TC_H_ROOT (0xFFFFFFFF) across all qdisc types, as suggested by Jamal.

Affected

35 ranges· showing 25
VendorProductVersion rangeFixed in
debianlinux< linux 6.1.133-1 (bookworm)linux 6.1.133-1 (bookworm)
debianlinux-6.1< linux 6.1.133-1 (bookworm)linux 6.1.133-1 (bookworm)
googlechrome_chrome
linuxlinux
linuxlinux>= 066a3b5b2346febf9a655b444567b7138e3bb939 < e05d9938b1b0ac40b6054cc5fa0ccbd9afd5ed4ce05d9938b1b0ac40b6054cc5fa0ccbd9afd5ed4c
linuxlinux>= 066a3b5b2346febf9a655b444567b7138e3bb939 < 7a82fe67a9f4d7123d8e5ba8f0f0806c286950067a82fe67a9f4d7123d8e5ba8f0f0806c28695006
linuxlinux>= 066a3b5b2346febf9a655b444567b7138e3bb939 < 003d92c91cdb5a64b25a9a74cb8543aac9a8bb48003d92c91cdb5a64b25a9a74cb8543aac9a8bb48
linuxlinux>= 066a3b5b2346febf9a655b444567b7138e3bb939 < e5ee00607bbfc97ef1526ea95b6b2458ac9e7cb7e5ee00607bbfc97ef1526ea95b6b2458ac9e7cb7
linuxlinux>= 066a3b5b2346febf9a655b444567b7138e3bb939 < 78533c4a29ac3aeddce4b481770beaaa4f3bfb6778533c4a29ac3aeddce4b481770beaaa4f3bfb67
linuxlinux>= 066a3b5b2346febf9a655b444567b7138e3bb939 < 5c3ca9cb48b51bd72bf76b8b05e24f3cd53db5e75c3ca9cb48b51bd72bf76b8b05e24f3cd53db5e7
linuxlinux>= 066a3b5b2346febf9a655b444567b7138e3bb939 < 94edfdfb9505ab608e86599d1d1e38c83816fc1c94edfdfb9505ab608e86599d1d1e38c83816fc1c
linuxlinux>= 066a3b5b2346febf9a655b444567b7138e3bb939 < 0c3057a5a04d07120b3d0ec9c79568fceb9c921e0c3057a5a04d07120b3d0ec9c79568fceb9c921e
linuxlinux_kernel
linuxlinux_kernel
linuxlinux_kernel
linuxlinux_kernel
linuxlinux_kernel
linuxlinux_kernel
linuxlinux_kernel
linuxlinux_kernel>= 0 < 5.10.237-15.10.237-1
linuxlinux_kernel>= 0 < 6.1.133-16.1.133-1
linuxlinux_kernel>= 0 < 6.12.20-16.12.20-1
linuxlinux_kernel>= 0 < 6.12.20-16.12.20-1
linuxlinux_kernel>= 0 < 5.4.0-216.2365.4.0-216.236
linuxlinux_kernel>= 0 < 5.15.0-140.1505.15.0-140.150

CVSS provenance

nvdv3.15.5MEDIUMCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
osv8.8HIGH
vendor_ubuntu8.8HIGH
vendor_debian5.5MEDIUM
vendor_redhat5.5MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.