CVE-2025-40083
Published: Oct 29, 2025
Modified: May 11, 2026
Description
In the Linux kernel, the following vulnerability has been resolved: net/sched: sch_qfq: Fix null-deref in agg_dequeue To prevent a potential crash in agg_dequeue (net/sched/sch_qfq.c) when cl->qdisc->ops->peek(cl->qdisc) returns NULL, we check the return value before using it, similar to the existing approach in sch_hfsc.c. To avoid code duplication, the following changes are made: 1. Changed qdisc_warn_nonwc(include/net/pkt_sched.h) into a static inline function. 2. Moved qdisc_peek_len from net/sched/sch_hfsc.c to include/net/pkt_sched.h so that sch_qfq can reuse it. 3. Applied qdisc_peek_len in agg_dequeue to avoid crashing.
| Vendor | Product | Versions |
|---|---|---|
Linux | Linux | affected 462dbc9101acd38e92eda93c0726857517a24bbd - < 71d84658a61322e5630c85c5388fc25e4a2d08b2affected 462dbc9101acd38e92eda93c0726857517a24bbd - < 99fc137f178797204d36ac860dd8b31e35baa2dfaffected 462dbc9101acd38e92eda93c0726857517a24bbd - < 1bed56f089f09b465420bf23bb32985c305cfc28affected 462dbc9101acd38e92eda93c0726857517a24bbd - < 3c2a8994807623c7655ece205667ae2cf74940aaaffected 462dbc9101acd38e92eda93c0726857517a24bbd - < 6ffa9d66187188e3068b5a3895e6ae1ee34f9199+2 more versions |
Linux | Linux | affected 3.8unaffected 0 - < 3.8unaffected 5.4.302 - <= 5.4.*unaffected 5.10.247 - <= 5.10.*unaffected 5.15.197 - <= 5.15.*+4 more versions |
References
Security Training
Train your team to recognize and prevent security threats with our comprehensive security awareness program.
Start TrainingVulnerability Scanning
Discover vulnerabilities in your applications and infrastructure before attackers do.
Scan Now