CVE-2025-37953 Details
Description
In the Linux kernel, the following vulnerability has been resolved: sch_htb: make htb_deactivate() idempotent Alan reported a NULL pointer dereference in htb_next_rb_node() after we made htb_qlen_notify() idempotent. It turns out in the following case it introduced some regression: htb_dequeue_tree(): |-> fq_codel_dequeue() |-> qdisc_tree_reduce_backlog() |-> htb_qlen_notify() |-> htb_deactivate() |-> htb_next_rb_node() |-> htb_deactivate() For htb_next_rb_node(), after calling the 1st htb_deactivate(), the clprio[prio]->ptr could be already set to NULL, which means htb_next_rb_node() is vulnerable here. For htb_deactivate(), although we checked qlen before calling it, in case of qlen==0 after qdisc_tree_reduce_backlog(), we may call it again which triggers the warning inside. To fix the issues here, we need to: 1) Make htb_deactivate() idempotent, that is, simply return if we already call it before. 2) Make htb_next_rb_node() safe against ptr==NULL. Many thanks to Alan for testing and for the reproducer.
A NULL pointer dereference vulnerability has been identified in the Linux kernel's sch_htb (Hierarchical Token Bucket) component. This issue arises from a regression introduced when making the htb_qlen_notify() function idempotent. The vulnerability occurs in the htb_next_rb_node() function, where a previously nullified pointer can lead to a dereference error. The problem is exacerbated by the htb_deactivate() function, which, despite checking the queue length, may be called multiple times under certain conditions, triggering a warning. The vulnerability can be reproduced by following the htb_dequeue_tree() process, which involves several function calls that ultimately lead to the NULL pointer dereference.
The vulnerability has been addressed by making the htb_deactivate() function idempotent, ensuring it can be safely called multiple times without causing issues, and by modifying the htb_next_rb_node() function to safely handle cases where the pointer is NULL.
Metrics
CVSS 4.0 Severity and Vector Strings:
No CVSS 4.0 data is available for this CVE.
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
No SSVC data is available for this CVE.
References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://git.kernel.org/stable/c/31ff70ad39485698cf779f2078132d80b57f6c07 | kernel.org | Patch |
| https://git.kernel.org/stable/c/3769478610135e82b262640252d90f6efb05be71 | kernel.org | Patch |
| https://git.kernel.org/stable/c/98cd7ed92753090a714f0802d4434314526fe61d | kernel.org | Patch |
| https://git.kernel.org/stable/c/99ff8a20fd61315bf9ae627440a5ff07d22ee153 | kernel.org | Patch |
| https://git.kernel.org/stable/c/a9945f7cf1709adc5d2d31cb6cfc85627ce299a8 | kernel.org | Patch |
| https://git.kernel.org/stable/c/c2d25fddd867ce20a266806634eeeb5c30cb520c | kernel.org | Patch |
| https://git.kernel.org/stable/c/c4792b9e38d2f61b07eac72f10909fa76130314b | kernel.org | Patch |
| https://git.kernel.org/stable/c/c928dd4f6bf0c25c72b11824a1e9ac9bd37296a0 | kernel.org | Patch |
| https://lists.debian.org/debian-lts-announce/2025/08/msg00010.html | CVE | Third Party Advisory |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-476 | NULL Pointer Dereference | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| linux linux kernel | 6.1.138 6.6.90 6.12.28 6.14.6 6.15 rc2 6.15 rc3 6.15 rc4 6.15 rc5 |
CPE
Remediation
| |
| debian debian linux | 11.0 |
CPE
Remediation
| |
Change History
6 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | kernel.org |
| Dec 17, 2025 | Initial Analysis | [email protected] |
| Nov 3, 2025 | CVE Modified | CVE |
| Aug 28, 2025 | CVE Modified | kernel.org |
| Jun 4, 2025 | CVE Modified | kernel.org |
| May 20, 2025 | New CVE Received | kernel.org |