Home

Description

In the Linux kernel, the following vulnerability has been resolved: net/sched: mqprio: fix stack out-of-bounds write in tc entry parsing TCA_MQPRIO_TC_ENTRY_INDEX is validated using NLA_POLICY_MAX(NLA_U32, TC_QOPT_MAX_QUEUE), which allows the value TC_QOPT_MAX_QUEUE (16). This leads to a 4-byte out-of-bounds stack write in the fp[] array, which only has room for 16 elements (0–15). Fix this by changing the policy to allow only up to TC_QOPT_MAX_QUEUE - 1.

PUBLISHED Reserved 2025-04-16 | Published 2025-08-19 | Updated 2025-09-29 | Assigner Linux

Product status

Default status
unaffected

f62af20bed2d9e824f51cfc97ff01bc261f40e58 before 39491e859fd494d0b51adc5c7d54c8a7dcf1d198
affected

f62af20bed2d9e824f51cfc97ff01bc261f40e58 before d00e4125680f7074c4f42ce3c297336f23128e70
affected

f62af20bed2d9e824f51cfc97ff01bc261f40e58 before 66fc2ebdd9d5dd6e5a9c7edeace5a61a0ab2cd86
affected

f62af20bed2d9e824f51cfc97ff01bc261f40e58 before f1a9dbcb7d17bf0abb325cdc984957cfabc59693
affected

f62af20bed2d9e824f51cfc97ff01bc261f40e58 before ffd2dc4c6c49ff4f1e5d34e454a6a55608104c17
affected

Default status
affected

6.4
affected

Any version before 6.4
unaffected

6.6.102
unaffected

6.12.42
unaffected

6.15.10
unaffected

6.16.1
unaffected

6.17
unaffected

References

git.kernel.org/...c/39491e859fd494d0b51adc5c7d54c8a7dcf1d198

git.kernel.org/...c/d00e4125680f7074c4f42ce3c297336f23128e70

git.kernel.org/...c/66fc2ebdd9d5dd6e5a9c7edeace5a61a0ab2cd86

git.kernel.org/...c/f1a9dbcb7d17bf0abb325cdc984957cfabc59693

git.kernel.org/...c/ffd2dc4c6c49ff4f1e5d34e454a6a55608104c17

cve.org (CVE-2025-38568)

nvd.nist.gov (CVE-2025-38568)

Download JSON