Security readout for executives and security teams
Plain-English summary
This Linux kernel flaw affects Airoha Ethernet traffic-shaping cleanup. Deleting hardware-offloaded HTB queues can produce a kernel warning because the driver reports the wrong queue identifier. The supplied CVSS rating is 7.8, although the public description demonstrates a warning rather than confirmed compromise or service failure.
Executive priority
Prioritize targeted remediation rather than an estate-wide emergency response. Identify Airoha-based networking systems first, especially appliances using offloaded traffic shaping. Patch promptly where exposure exists. The high score warrants attention, but absent KEV listing or demonstrated compromise, current evidence does not support declaring an active-exploitation crisis.
Technical view
The airoha_eth driver's airoha_tc_get_htb_get_leaf_queue() routine incorrectly reports the queue identifier while deleting HTB-offloaded leaf or root qdiscs. The documented trigger reaches qdisc destruction through rtnetlink and emits a kernel warning. The cited stable-kernel commits correct the reporting behavior. No CWE is supplied.
Likely exposure
Exposure requires an affected Linux kernel, Airoha Ethernet hardware or driver, and HTB hardware-offload configuration. The CVSS vector describes local, low-privilege access without user interaction, so this is not presented as a directly remote network vulnerability. The bundle's flattened version data makes exact release boundaries unclear.
Exploitation context
CISA KEV status is false, and the supplied sources provide no evidence of active exploitation or a public weaponized exploit. They document a reproducible kernel warning during traffic-control cleanup. The high CVSS impact claims should therefore be treated cautiously until vendor analysis establishes consequences beyond the warning.
Researcher notes
The observable evidence is a warning during HTB qdisc teardown caused by incorrect qid reporting. No CWE or detailed security-impact analysis is supplied. Researchers should distinguish the demonstrated warning from the CVSS assertion of complete confidentiality, integrity, and availability impact, and verify exact affected ranges from authoritative kernel metadata.
Mitigation direction
Apply a vendor or distribution kernel update containing the cited stable fix.
Confirm exact affected and fixed versions with the Linux or distribution security guidance.
Prioritize systems using the Airoha Ethernet driver with HTB hardware offload.
Consider disabling unnecessary HTB hardware offload until remediation, subject to operational testing.
Validation and detection
Inventory kernel versions and identify systems loading the Airoha Ethernet driver.
Determine whether HTB qdiscs use hardware offload on those systems.
Compare deployed kernel source or packages with the two cited fix commits.
Review kernel logs for warnings associated with qdisc destruction or traffic-control changes.
Regression-test traffic-shaping removal safely after updating.
Generated from the cited source records. This long-tail analysis has not been individually reviewed by a named human.
Potential ATT&CK relevance
Conservative CVE-to-ATT&CK context
These mappings and lookup hints may be relevant to the vulnerability behavior, CWE, affected product, or exposure path. Glexia-inferred context is not an official MITRE, ATT&CK, CWE, or CVE Program mapping.
ATT&CK lookup starting points
Use these exact CWE pages and searches to review the Glexia ATT&CK library from this CVE's weakness and description context.
cve · low confidence lookup
CVE-2025-22061 mapping review
Open the CVE-to-ATT&CK bridge for reviewed, inferred, or future official mappings tied to this CVE.
These fields come from the CVE record and ADP containers, not from Glexia's Take. They preserve time-varying source decisions such as CISA SSVC, KEV status, CVSS metrics, and provider references.
1CVSS vectors
3Timeline events
0ADP providers
3Source links
CVSS vector scores
1 official score
We collect every scored CVSS vector available in the official CNA and ADP containers. When more than one version is present, the table keeps the source vectors side by side instead of collapsing them into the highest score.