cbcvebase.
CVE-2025-40083
published 2025-10-29

CVE-2025-40083: In the Linux kernel, the following vulnerability has been resolved: net/sched: sch_qfq: Fix null-deref in agg_dequeue To prevent a potential crash in…

PriorityP420high7.8
EPSS
0.19%
9.2th percentile
In the Linux kernel, the following vulnerability has been resolved: net/sched: sch_qfq: Fix null-deref in agg_dequeue To prevent a potential crash in agg_dequeue (net/sched/sch_qfq.c) when cl->qdisc->ops->peek(cl->qdisc) returns NULL, we check the return value before using it, similar to the existing approach in sch_hfsc.c. To avoid code duplication, the following changes are made: 1. Changed qdisc_warn_nonwc(include/net/pkt_sched.h) into a static inline function. 2. Moved qdisc_peek_len from net/sched/sch_hfsc.c to include/net/pkt_sched.h so that sch_qfq can reuse it. 3. Applied qdisc_peek_len in agg_dequeue to avoid crashing.

Affected

26 ranges· showing 25
VendorProductVersion rangeFixed in
debianlinux< linux 6.1.159-1 (bookworm)linux 6.1.159-1 (bookworm)
debianlinux-6.1< linux 6.1.159-1 (bookworm)linux 6.1.159-1 (bookworm)
linuxlinux
linuxlinux>= 462dbc9101acd38e92eda93c0726857517a24bbd < 71d84658a61322e5630c85c5388fc25e4a2d08b271d84658a61322e5630c85c5388fc25e4a2d08b2
linuxlinux>= 462dbc9101acd38e92eda93c0726857517a24bbd < 99fc137f178797204d36ac860dd8b31e35baa2df99fc137f178797204d36ac860dd8b31e35baa2df
linuxlinux>= 462dbc9101acd38e92eda93c0726857517a24bbd < 1bed56f089f09b465420bf23bb32985c305cfc281bed56f089f09b465420bf23bb32985c305cfc28
linuxlinux>= 462dbc9101acd38e92eda93c0726857517a24bbd < 3c2a8994807623c7655ece205667ae2cf74940aa3c2a8994807623c7655ece205667ae2cf74940aa
linuxlinux>= 462dbc9101acd38e92eda93c0726857517a24bbd < 6ffa9d66187188e3068b5a3895e6ae1ee34f91996ffa9d66187188e3068b5a3895e6ae1ee34f9199
linuxlinux>= 462dbc9101acd38e92eda93c0726857517a24bbd < 6ff8e74c8f8a68ec07ef837b95425dfe900d060f6ff8e74c8f8a68ec07ef837b95425dfe900d060f
linuxlinux>= 462dbc9101acd38e92eda93c0726857517a24bbd < dd831ac8221e691e9e918585b1003c7071df0379dd831ac8221e691e9e918585b1003c7071df0379
linuxlinux_kernel>= 0 < 5.10.247-15.10.247-1
linuxlinux_kernel>= 0 < 6.1.159-16.1.159-1
linuxlinux_kernel>= 0 < 6.12.57-16.12.57-1
linuxlinux_kernel>= 0 < 6.16.3-16.16.3-1
linuxlinux_kernel>= 0 < 5.15.0-173.1835.15.0-173.183
linuxlinux_kernel>= 0 < 6.8.0-106.1066.8.0-106.106
linuxlinux_kernel>= 3.8.0 < 5.4.3025.4.302
linuxlinux_kernel>= 5.11.0 < 5.15.1975.15.197
linuxlinux_kernel>= 5.16.0 < 6.1.1596.1.159
linuxlinux_kernel>= 5.5.0 < 5.10.2475.10.247
linuxlinux_kernel>= 6.2.0 < 6.6.1166.6.116
linuxlinux_kernel>= 6.7.0 < 6.12.576.12.57
msrcazl3_kernel_6.6.104.2-4_on_azure_linux_3.0
msrcazl3_kernel_6.6.112.1-2_on_azure_linux_3.0
ubuntulinux-azure-5.15

CVSS provenance

osv7.8HIGH
vendor_ubuntu7.8HIGH
vendor_redhat5.9MEDIUM
vendor_msrc5.5MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.