Executive Summary

Informations
Name CVE-2025-21703 First vendor Publication 2025-02-18
Vendor Cve Last vendor Modification 2025-02-21

Security-Database Scoring CVSS v3

Cvss vector : N/A
Overall CVSS Score NA
Base Score NA Environmental Score NA
impact SubScore NA Temporal Score NA
Exploitabality Sub Score NA
 
Calculate full CVSS 3.0 Vectors scores

Security-Database Scoring CVSS v2

Cvss vector :
Cvss Base Score N/A Attack Range N/A
Cvss Impact Score N/A Attack Complexity N/A
Cvss Expoit Score N/A Authentication N/A
Calculate full CVSS 2.0 Vectors scores

Detail

In the Linux kernel, the following vulnerability has been resolved:

netem: Update sch->q.qlen before qdisc_tree_reduce_backlog()

qdisc_tree_reduce_backlog() notifies parent qdisc only if child qdisc becomes empty, therefore we need to reduce the backlog of the child qdisc before calling it. Otherwise it would miss the opportunity to call cops->qlen_notify(), in the case of DRR, it resulted in UAF since DRR uses ->qlen_notify() to maintain its active list.

Original Source

Url : http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-21703

Sources (Detail)

https://git.kernel.org/stable/c/1f8e3f4a4b8b90ad274dfbc66fc7d55cb582f4d5
https://git.kernel.org/stable/c/6312555249082d6d8cc5321ff725df05482d8b83
https://git.kernel.org/stable/c/638ba5089324796c2ee49af10427459c2de35f71
https://git.kernel.org/stable/c/7b79ca9a1de6a428d486ff52fb3d602321c08f55
https://git.kernel.org/stable/c/839ecc583fa00fab785fde1c85a326743657fd32
Source Url

Alert History

If you want to see full details history, please login or register.
0
1
Date Informations
2025-02-21 17:20:30
  • Multiple Updates
2025-02-18 21:20:28
  • First insertion