cbcvebase.
CVE-2025-37932
published 2025-05-20

CVE-2025-37932: In the Linux kernel, the following vulnerability has been resolved: sch_htb: make htb_qlen_notify() idempotent htb_qlen_notify() always deactivates the HTB…

PriorityP418medium5.5CVSS 3.1
AVLACLPRLUINSUCNINAH
EPSS
0.19%
9.3th percentile
In the Linux kernel, the following vulnerability has been resolved: sch_htb: make htb_qlen_notify() idempotent htb_qlen_notify() always deactivates the HTB class and in fact could trigger a warning if it is already deactivated. Therefore, it is not idempotent and not friendly to its callers, like fq_codel_dequeue(). Let's make it idempotent to ease qdisc_tree_reduce_backlog() callers' life.

Affected

35 ranges· showing 25
VendorProductVersion rangeFixed in
debiandebian_linux
debianlinux< linux 6.1.140-1 (bookworm)linux 6.1.140-1 (bookworm)
debianlinux-6.1< linux 6.1.140-1 (bookworm)linux 6.1.140-1 (bookworm)
linuxlinux
linuxlinux>= 959466588aa7f84ccf79ae36a1d89542eaf9aaec < e6b45f4de763b00dc1c55e685e2dd1aaf525d3c1e6b45f4de763b00dc1c55e685e2dd1aaf525d3c1
linuxlinux>= 959466588aa7f84ccf79ae36a1d89542eaf9aaec < 32ae12ce6a9f6bace186ca7335220ff59b6cc3cd32ae12ce6a9f6bace186ca7335220ff59b6cc3cd
linuxlinux>= 959466588aa7f84ccf79ae36a1d89542eaf9aaec < 967955c9e57f8eebfccc298037d4aaf3d42bc1c9967955c9e57f8eebfccc298037d4aaf3d42bc1c9
linuxlinux>= 959466588aa7f84ccf79ae36a1d89542eaf9aaec < 73cf6af13153d62f9b76eff422eea79dbc70f15e73cf6af13153d62f9b76eff422eea79dbc70f15e
linuxlinux>= 959466588aa7f84ccf79ae36a1d89542eaf9aaec < bbbf5e0f87078b715e7a665d662a2c0e77f044aebbbf5e0f87078b715e7a665d662a2c0e77f044ae
linuxlinux>= 959466588aa7f84ccf79ae36a1d89542eaf9aaec < 0a188c0e197383683fd093ab1ea6ce9a5869a6ea0a188c0e197383683fd093ab1ea6ce9a5869a6ea
linuxlinux>= 959466588aa7f84ccf79ae36a1d89542eaf9aaec < a61f1b5921761fbaf166231418bc1db301e5bf59a61f1b5921761fbaf166231418bc1db301e5bf59
linuxlinux>= 959466588aa7f84ccf79ae36a1d89542eaf9aaec < 5ba8b837b522d7051ef81bacf3d95383ff8edce55ba8b837b522d7051ef81bacf3d95383ff8edce5
linuxlinux_kernel< 5.4.2945.4.294
linuxlinux_kernel
linuxlinux_kernel>= 0 < 5.10.244-15.10.244-1
linuxlinux_kernel>= 0 < 6.1.140-16.1.140-1
linuxlinux_kernel>= 0 < 6.12.29-16.12.29-1
linuxlinux_kernel>= 0 < 6.12.29-16.12.29-1
linuxlinux_kernel>= 0 < 5.15.0-143.1535.15.0-143.153
linuxlinux_kernel>= 0 < 6.8.0-63.666.8.0-63.66
linuxlinux_kernel>= 0 < 6.14.0-23.236.14.0-23.23
linuxlinux_kernel>= 0 < 4.4.0-270.3044.4.0-270.304
linuxlinux_kernel>= 0 < 4.15.0-239.2514.15.0-239.251
linuxlinux_kernel>= 0 < 5.4.0-219.2395.4.0-219.239
linuxlinux_kernel>= 5.11 < 5.15.1905.15.190

CVSS provenance

nvdv3.15.5MEDIUMCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
osv8.8HIGH
vendor_ubuntu8.8HIGH
vendor_debian5.5MEDIUM
vendor_redhat5.5MEDIUM
vendor_msrc2.5LOW
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.