CVE-2025-38193 Details
Description
In the Linux kernel, the following vulnerability has been resolved: net_sched: sch_sfq: reject invalid perturb period Gerrard Tai reported that SFQ perturb_period has no range check yet, and this can be used to trigger a race condition fixed in a separate patch. We want to make sure ctl->perturb_period * HZ will not overflow and is positive. tc qd add dev lo root sfq perturb -10 # negative value : error Error: sch_sfq: invalid perturb period. tc qd add dev lo root sfq perturb 1000000000 # too big : error Error: sch_sfq: invalid perturb period. tc qd add dev lo root sfq perturb 2000000 # acceptable value tc -s -d qd sh dev lo qdisc sfq 8005: root refcnt 2 limit 127p quantum 64Kb depth 127 flows 128 divisor 1024 perturb 2000000sec Sent 0 bytes 0 pkt (dropped 0, overlimits 0 requeues 0) backlog 0b 0p requeues 0
A vulnerability in the Linux kernel's Simple Fair Queueing (SFQ) scheduler has been addressed. The issue arose because the SFQ perturb_period parameter lacked proper range validation, allowing for the possibility of a race condition. This vulnerability could be exploited by setting the perturb_period to an invalid value, such as a negative number or a value too large, which would trigger an error. However, an acceptable value could be used to bypass this check.
Metrics
CVSS 4.0 Severity and Vector Strings:
No CVSS 4.0 data is available for this CVE.
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
No SSVC data is available for this CVE.
References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://git.kernel.org/stable/c/0357da9149eac621f39e235a135ebf155f01f7c3 | kernel.org | Patch |
| https://git.kernel.org/stable/c/2254d038dab9c194fe6a4b1ce31034f42e91a6e5 | kernel.org | Patch |
| https://git.kernel.org/stable/c/590b2d7d0beadba2aa576708a05a05f0aae39295 | kernel.org | Patch |
| https://git.kernel.org/stable/c/7ca52541c05c832d32b112274f81a985101f9ba8 | kernel.org | Patch |
| https://git.kernel.org/stable/c/956b5aebb349449b38d920d444ca1392d43719d1 | kernel.org | Patch |
| https://git.kernel.org/stable/c/b11a50544af691b787384089b68f740ae20a441b | kernel.org | Patch |
| https://git.kernel.org/stable/c/e0936ff56be4e08ad5b60ec26971eae0c40af305 | kernel.org | Patch |
| https://git.kernel.org/stable/c/f9b97d466e6026ccbdda30bb5b71965b67ccbc82 | kernel.org | Patch |
| https://lists.debian.org/debian-lts-announce/2025/10/msg00007.html | CVE | Third Party Advisory |
| https://lists.debian.org/debian-lts-announce/2025/10/msg00008.html | CVE | Third Party Advisory |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-190 | Integer Overflow or Wraparound | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| linux linux kernel | >= 2.6.13, < 5.4.297 >= 5.5, < 5.10.240 >= 5.11, < 5.15.186 >= 5.16, < 6.1.142 >= 6.2, < 6.6.95 >= 6.7, < 6.12.35 >= 6.13, < 6.15.4 2.6.12 - 2.6.12 rc2 2.6.12 rc3 2.6.12 rc4 2.6.12 rc5 6.16 rc1 |
CPE
Remediation
| |
| debian debian linux | 11.0 |
CPE
Remediation
| |
Change History
7 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jul 30, 2026 | CVE Modified | kernel.org |
| Jun 17, 2026 | CVE Modified | kernel.org |
| Dec 18, 2025 | Initial Analysis | [email protected] |
| Nov 3, 2025 | CVE Modified | CVE |
| Aug 28, 2025 | CVE Modified | kernel.org |
| Jul 17, 2025 | CVE Modified | kernel.org |
| Jul 4, 2025 | New CVE Received | kernel.org |