Answer in brief
CVE-2024-53057 records a Unknown severity vulnerability in net/sched: stop qdisc_tree_reduce_backlog on TC_H_ROOT. The current sources do not mark it as known exploited. The current feed maps Linux/Linux (generic), Linux/Linux (generic), Siemens/RUGGEDCOM RST2428P (generic), Siemens/SCALANCE XC-300/XR-300/XC-400/XR-500WG/XR-500 family (generic) and additional mapped packages. Check affected ranges and fixed versions before updating.
Analysis pending evidence review
HOL Guard separates source facts from reviewed analysis. See the methodology.
A CVSS score is not reported in the current record. The current sources do not mark it as known exploited. Treat this as a source-backed prioritization signal, not a statement about your environment.
Analysis status
Analysis pending evidence review
Factual feed record only; HOL analysis is not approved for indexing. Read the methodology.
The current feed maps Linux/Linux (generic), Linux/Linux (generic), Siemens/RUGGEDCOM RST2428P (generic), Siemens/SCALANCE XC-300/XR-300/XC-400/XR-500WG/XR-500 family (generic) and additional mapped packages. Check affected ranges and fixed versions before updating.
| Package | Affected range | Fixed version |
|---|---|---|
| Linux/Linuxgeneric | >=066a3b5b2346febf9a655b444567b7138e3bb939 <e7f9a6f97eb067599a74f3bcb6761976b0ed303e || >=066a3b5b2346febf9a655b444567b7138e3bb939 <dbe778b08b5101df9e89bc06e0a3a7ecd2f4ef20 || >=066a3b5b2346febf9a655b444567b7138e3bb939 <ce691c814bc7a3c30c220ffb5b7422715458fd9b || >=066a3b5b2346febf9a655b444567b7138e3bb939 <05df1b1dff8f197f1c275b57ccb2ca33021df552 || >=066a3b5b2346febf9a655b444567b7138e3bb939 <580b3189c1972aff0f993837567d36392e9d981b || >=066a3b5b2346febf9a655b444567b7138e3bb939 <597cf9748c3477bf61bc35f0634129f56764ad24 || >=066a3b5b2346febf9a655b444567b7138e3bb939 <9995909615c3431a5304c1210face5f268d24dba || >=066a3b5b2346febf9a655b444567b7138e3bb939 <2e95c4384438adeaa772caa560244b1a2efef816 | e7f9a6f97eb067599a74f3bcb6761976b0ed303e, dbe778b08b5101df9e89bc06e0a3a7ecd2f4ef20, ce691c814bc7a3c30c220ffb5b7422715458fd9b, 05df1b1dff8f197f1c275b57ccb2ca33021df552, 580b3189c1972aff0f993837567d36392e9d981b, 597cf9748c3477bf61bc35f0634129f56764ad24, 9995909615c3431a5304c1210face5f268d24dba, 2e95c4384438adeaa772caa560244b1a2efef816 |
| Linux/Linuxgeneric | 2.6.25 | Not reported |
| Siemens/RUGGEDCOM RST2428Pgeneric | >=0 <V3.2 | V3.2 |
| Siemens/SCALANCE XC-300/XR-300/XC-400/XR-500WG/XR-500 familygeneric | >=0 <V3.2 | V3.2 |
| Siemens/SCALANCE XCM-/XRM-/XCH-/XRH-300 familygeneric | >=0 <V3.2 | V3.2 |
| Siemens/SIMATIC S7-1500 CPU 1518-4 PN/DP MFPgeneric | >=V3.1.0 <V3.1.5 | V3.1.5 |
| Siemens/SIMATIC S7-1500 CPU 1518F-4 PN/DP MFPgeneric | >=V3.1.0 <V3.1.5 | V3.1.5 |
| Siemens/SIMATIC S7-1500 TM MFP - GNU/Linux subsystemgeneric | >=0 <* | * |
| Siemens/SIPLUS S7-1500 CPU 1518-4 PN/DP MFPgeneric | >=V3.1.0 <V3.1.5 | V3.1.5 |
Published upstream
Nov 19, 2024
Evidence: source:cvelist:source_dates:source-dates:recordSource modified
Aug 5, 2026
Evidence: source:cvelist:source_dates:source-dates:recordFirst seen by HOL
Aug 5, 2026
In the Linux kernel, the following vulnerability has been resolved: net/sched: stop qdisc_tree_reduce_backlog on TC_H_ROOT In qdisc_tree_reduce_backlog, Qdiscs with major handle ffff: are assumed to be either root or ingress. This assumption is bogus since it's valid to create egress qdiscs with major handle ffff: Budimir Markovic found that for qdiscs like DRR that maintain an active class list, it will cause a UAF with a dangling class pointer. In 066a3b5b2346, the concern was to avoid iterating over the ingress qdisc since its parent is itself. The proper fix is to stop when parent TC_H_ROOT is reached because the only way to retrieve ingress is when a hierarchy which does not contain a ffff: major handle call into qdisc_lookup with TC_H_MAJ(TC_H_ROOT). In the scenario where major ffff: is an egress qdisc in any of the tree levels, the updates will also propagate to TC_H_ROOT, which then the iteration must stop. net/sched/sch_api.c | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-)
Quoted source text, attributed separately from HOL analysis.