CVE-2025-37752: net_sched: sch_sfq: move the limit validation
In the Linux kernel, the following vulnerability has been resolved:
net_sched: sch_sfq: move the limit validation
It is not sufficient to directly validate the limit on the data that
the user passes as it can be updated based on how the other parameters
are changed.
Move the check at the end of the configuration update process to also
catch scenarios where the limit is indirectly updated, for example
with the following configurations:
tc qdisc add dev dummy0 handle 1: root sfq limit 2 flows 1 depth 1
tc qdisc add dev dummy0 handle 1: root sfq limit 2 flows 1 divisor 1
This fixes the following syzkaller reported crash:
------------[ cut here ]------------
UBSAN: array-index-out-of-bounds in net/sched/sch_sfq.c:203:6
index 65535 is out of range for type 'struct sfq_head[128]'
CPU: 1 UID: 0 PID: 3037 Comm: syz.2.16 Not tainted 6.14.0-rc2-syzkaller #0
Hardware name: Google Google Compute Engine/Google Compute Engine, BIOS Google 12/27/2024
Call Trace:
<TASK>
__dump_stack lib/dump_stack.c:94 [inline]
dump_stack_lvl+0x201/0x300 lib/dump_stack.c:120
ubsan_epilogue lib/ubsan.c:231 [inline]
__ubsan_handle_out_of_bounds+0xf5/0x120 lib/ubsan.c:429
sfq_link net/sched/sch_sfq.c:203 [inline]
sfq_dec+0x53c/0x610 net/sched/sch_sfq.c:231
sfq_dequeue+0x34e/0x8c0 net/sched/sch_sfq.c:493
sfq_reset+0x17/0x60 net/sched/sch_sfq.c:518
qdisc_reset+0x12e/0x600 net/sched/sch_generic.c:1035
tbf_reset+0x41/0x110 net/sched/sch_tbf.c:339
qdisc_reset+0x12e/0x600 net/sched/sch_generic.c:1035
dev_reset_queue+0x100/0x1b0 net/sched/sch_generic.c:1311
netdev_for_each_tx_queue include/linux/netdevice.h:2590 [inline]
dev_deactivate_many+0x7e5/0xe70 net/sched/sch_generic.c:1375
Security readout for executives and security teams
Plain-English summary
A Linux traffic-control flaw can let unsafe SFQ parameter combinations bypass an early validation check, leading to an out-of-bounds kernel access and crash. The supplied CVSS rates potential confidentiality, integrity, and availability impact as high, but the concrete evidence provided is a syzkaller-generated crash rather than demonstrated compromise.
Executive priority
Treat this as a high-priority local kernel issue, especially on shared or multi-tenant systems with delegated network administration. Patch through supported distribution channels promptly. Emergency internet-facing containment is not justified by the supplied evidence because the vulnerability is local and active exploitation is unconfirmed.
Technical view
SFQ configuration values could indirectly change the queue limit after it was validated. This allowed an invalid internal index, with syzkaller observing index 65535 against a 128-element sfq_head array during queue reset. Stable-kernel commits move validation to the end of configuration processing so derived values are checked.
Likely exposure
Exposure is limited to Linux systems running an affected kernel where a local actor can modify SFQ traffic-control configuration. The source bundle identifies affected release and commit data, but its version presentation is insufficient for confidently mapping every distribution package. Internet reachability alone does not establish exposure.
Exploitation context
The CVSS vector describes a local, low-complexity, low-privilege attack requiring no user interaction. The supplied evidence demonstrates a syzkaller-triggered kernel crash. The CVE is not marked as KEV, and no cited source reports active exploitation or a weaponized exploit.
Researcher notes
The strongest demonstrated outcome is an array-index-out-of-bounds condition in sch_sfq.c during reset or dequeue processing. The supplied CVSS asserts broader security impact, but no source demonstrates privilege escalation, code execution, or data compromise. Version applicability should be verified through distribution package metadata and the referenced stable commits.
Mitigation direction
Install a vendor-supported kernel containing the applicable stable-kernel fix.
Consult your Linux distributor's advisory for package-specific fixed versions.
Restrict untrusted users and workloads from changing traffic-control qdisc configuration.
Prioritize shared hosts where delegated workloads can administer network settings.
Validation and detection
Inventory kernel versions across Linux hosts and container platforms.
Map installed distribution packages against vendor advisories and fixed builds.
Identify systems permitting non-administrators or workloads to configure SFQ qdiscs.
Confirm the applicable stable fix is present after updating.
Monitor affected systems for kernel out-of-bounds or SFQ-related crash reports.
Generated from the cited source records. This long-tail analysis has not been individually reviewed by a named human.
Potential ATT&CK relevance
Conservative CVE-to-ATT&CK context
These mappings and lookup hints may be relevant to the vulnerability behavior, CWE, affected product, or exposure path. Glexia-inferred context is not an official MITRE, ATT&CK, CWE, or CVE Program mapping.
ATT&CK lookup starting points
Use these exact CWE pages and searches to review the Glexia ATT&CK library from this CVE's weakness and description context.
cve · low confidence lookup
CVE-2025-37752 mapping review
Open the CVE-to-ATT&CK bridge for reviewed, inferred, or future official mappings tied to this CVE.
These fields come from the CVE record and ADP containers, not from Glexia's Take. They preserve time-varying source decisions such as CISA SSVC, KEV status, CVSS metrics, and provider references.
1CVSS vectors
3Timeline events
1ADP providers
11Source links
CVSS vector scores
1 official score
We collect every scored CVSS vector available in the official CNA and ADP containers. When more than one version is present, the table keeps the source vectors side by side instead of collapsing them into the highest score.