CVE-2025-38568
Published: Aug 19, 2025
Modified: May 11, 2026
Description
In the Linux kernel, the following vulnerability has been resolved: net/sched: mqprio: fix stack out-of-bounds write in tc entry parsing TCA_MQPRIO_TC_ENTRY_INDEX is validated using NLA_POLICY_MAX(NLA_U32, TC_QOPT_MAX_QUEUE), which allows the value TC_QOPT_MAX_QUEUE (16). This leads to a 4-byte out-of-bounds stack write in the fp[] array, which only has room for 16 elements (0–15). Fix this by changing the policy to allow only up to TC_QOPT_MAX_QUEUE - 1.
| Vendor | Product | Versions |
|---|---|---|
Linux | Linux | affected f62af20bed2d9e824f51cfc97ff01bc261f40e58 - < 39491e859fd494d0b51adc5c7d54c8a7dcf1d198affected f62af20bed2d9e824f51cfc97ff01bc261f40e58 - < d00e4125680f7074c4f42ce3c297336f23128e70affected f62af20bed2d9e824f51cfc97ff01bc261f40e58 - < 66fc2ebdd9d5dd6e5a9c7edeace5a61a0ab2cd86affected f62af20bed2d9e824f51cfc97ff01bc261f40e58 - < f1a9dbcb7d17bf0abb325cdc984957cfabc59693affected f62af20bed2d9e824f51cfc97ff01bc261f40e58 - < ffd2dc4c6c49ff4f1e5d34e454a6a55608104c17 |
Linux | Linux | affected 6.4unaffected 0 - < 6.4unaffected 6.6.102 - <= 6.6.*unaffected 6.12.42 - <= 6.12.*unaffected 6.15.10 - <= 6.15.*+2 more versions |
References
Security Training
Train your team to recognize and prevent security threats with our comprehensive security awareness program.
Start TrainingVulnerability Scanning
Discover vulnerabilities in your applications and infrastructure before attackers do.
Scan Now