-

CVE-2025-38568

In the Linux kernel, the following vulnerability has been resolved:

net/sched: mqprio: fix stack out-of-bounds write in tc entry parsing

TCA_MQPRIO_TC_ENTRY_INDEX is validated using
NLA_POLICY_MAX(NLA_U32, TC_QOPT_MAX_QUEUE), which allows the value
TC_QOPT_MAX_QUEUE (16). This leads to a 4-byte out-of-bounds stack
write in the fp[] array, which only has room for 16 elements (0–15).

Fix this by changing the policy to allow only up to TC_QOPT_MAX_QUEUE - 1.

Verknüpft mit AI von unstrukturierten Daten zu bestehenden CPE der NVD
Diese Information steht angemeldeten Benutzern zur Verfügung.
Daten sind bereitgestellt durch das CVE Programm von einer CVE Numbering Authority (CNA) (Unstrukturiert).
HerstellerLinux
Produkt Linux
Default Statusunaffected
Version < 39491e859fd494d0b51adc5c7d54c8a7dcf1d198
Version f62af20bed2d9e824f51cfc97ff01bc261f40e58
Status affected
Version < d00e4125680f7074c4f42ce3c297336f23128e70
Version f62af20bed2d9e824f51cfc97ff01bc261f40e58
Status affected
Version < 66fc2ebdd9d5dd6e5a9c7edeace5a61a0ab2cd86
Version f62af20bed2d9e824f51cfc97ff01bc261f40e58
Status affected
Version < f1a9dbcb7d17bf0abb325cdc984957cfabc59693
Version f62af20bed2d9e824f51cfc97ff01bc261f40e58
Status affected
Version < ffd2dc4c6c49ff4f1e5d34e454a6a55608104c17
Version f62af20bed2d9e824f51cfc97ff01bc261f40e58
Status affected
HerstellerLinux
Produkt Linux
Default Statusaffected
Version 6.4
Status affected
Version < 6.4
Version 0
Status unaffected
Version <= 6.6.*
Version 6.6.102
Status unaffected
Version <= 6.12.*
Version 6.12.42
Status unaffected
Version <= 6.15.*
Version 6.15.10
Status unaffected
Version <= 6.16.*
Version 6.16.1
Status unaffected
Version <= *
Version 6.17-rc1
Status unaffected
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.03% 0.071
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String